Summary
The remote host is missing updates announced in
advisory GLSA 200603-02.
Solution
All teTex users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-text/tetex-2.0.2-r8'
All CSTeX users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-text/cstetex-2.0.2-r2'
All pTeX users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-text/ptex-3.1.5-r1'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200603-02 http://bugs.gentoo.org/show_bug.cgi?id=115775
http://www.gentoo.org/security/en/glsa/glsa-200512-08.xml http://scary.beasts.org/security/CESA-2005-003.txt
Insight
CSTeTeX, pTeX, and teTeX include vulnerable XPdf code to handle PDF files, making them vulnerable to the execution of arbitrary code.
Severity
Classification
-
CVE CVE-2005-3193 -
CVSS Base Score: 5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
Related Vulnerabilities