DSA-222-1 xpdf -- integer overflow

Related Vulnerabilities: CVE-2002-1384  

iDEFENSE discovered an integer overflow in the pdftops filter from the xpdf package that can be exploited to gain the privileges of the target user. This can lead to gaining unauthorized access to the 'lp' user if the pdftops program is part of the print filter. For the current stable distribution (woody) this problem has been fixed in version 1.00-3.1. For the old stable distribution (potato) this problem has been fixed in version 0.90-8.1. For the unstable distribution (sid) this problem has been fixed in version 2.01-2. We recommend that you upgrade your xpdf package.

Debian Security Advisory

DSA-222-1 xpdf -- integer overflow

Date Reported:
06 Jan 2003
Affected Packages:
xpdf
Vulnerable:
Yes
Security database references:
In the Bugtraq database (at SecurityFocus): BugTraq ID 6475.
In Mitre's CVE dictionary: CVE-2002-1384.
More information:

iDEFENSE discovered an integer overflow in the pdftops filter from the xpdf package that can be exploited to gain the privileges of the target user. This can lead to gaining unauthorized access to the 'lp' user if the pdftops program is part of the print filter.

For the current stable distribution (woody) this problem has been fixed in version 1.00-3.1.

For the old stable distribution (potato) this problem has been fixed in version 0.90-8.1.

For the unstable distribution (sid) this problem has been fixed in version 2.01-2.

We recommend that you upgrade your xpdf package.

Fixed in:

Debian GNU/Linux 2.2 (potato)

Source:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90-8.1.dsc
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90-8.1.diff.gz
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90-8.1_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90-8.1_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90-8.1_i386.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90-8.1_m68k.deb
PowerPC:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90-8.1_powerpc.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_0.90-8.1_sparc.deb

Debian GNU/Linux 3.0 (woody)

Source:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_1.00-3.1.dsc
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_1.00-3.1.diff.gz
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_1.00.orig.tar.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-common_1.00-3.1_all.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf_1.00-3.1_all.deb
Alpha:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_alpha.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_arm.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_i386.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_ia64.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_hppa.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_m68k.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_mips.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_mipsel.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_powerpc.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_s390.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-reader_1.00-3.1_sparc.deb
http://security.debian.org/pool/updates/main/x/xpdf/xpdf-utils_1.00-3.1_sparc.deb

MD5 checksums of the listed files are available in the original advisory.