Summary
The remote host is missing updates announced in
advisory GLSA 200710-20.
Solution
PDFKit and ImageKits are not maintained upstream, so the packages were masked in Portage. We recommend that users unmerge PDFKit and ImageKits:
# emerge --unmerge gnustep-libs/pdfkit
# emerge --unmerge gnustep-libs/imagekits
As an alternative, users should upgrade their systems to use PopplerKit instead of PDFKit and Vindaloo instead of ViewPDF.
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200710-20 http://bugs.gentoo.org/show_bug.cgi?id=188185
http://www.gentoo.org/security/en/glsa/glsa-200709-12.xml
Insight
PDFKit and ImageKits are vulnerable to an integer overflow and a stack overflow allowing for the user-assisted execution of arbitrary code.
Severity
Classification
-
CVE CVE-2007-3387 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities