|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-0888: xpdf and code based on it | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Sebastian Krahmer <krahmer> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | adrian.schroeter, dmueller, gnome-bugs, ke, nadvornik, qa-bugs, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVSSv2:NVD:CVE-2004-0888:10.0:(AV:N/AC:L/Au:N/C:C/I:C/A:C) CVSSv2:RedHat:CVE-2004-0888:5.8:(AV:A/AC:L/Au:N/C:P/I:P/A:P) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | 58082 | ||
| Bug Blocks: | |||
| Attachments: |
The patch for the issues in the advisory
kpdf-CESA-2004-007.diff patchinfo file for box New patch for the issues described in advisory plus a few more I found. |
||
|
Description
Sebastian Krahmer
2004-09-10 17:20:03 UTC
<!-- SBZ_reproduce --> ... In addition to xpdf, gpdf and kpdf "pdftohtml" is affected, too. Created attachment 23923 [details]
The patch for the issues in the advisory
I created this fix, sent it to vendor-sec and nobody complained yet,
so i assume its correct :-)
Ok, can you please go ahead with the patch? The fix should also be suitable for the kpdf and other derived pdf viewers. the patch got partly applied for 9.2. kpdf has some rewritten code it seems, at least it uses C++ classes, xpdf doesn't seem to have some. xpdf 2 is the finest C++ code (with classes) ever :-) It would be great, if a C++/security guru would fix pdftohtml. The next 2 or 3 days, I'm mostly busy with SL 9.2 (translations, release-notes, testing, other packages). oh.. anyway, one hunk seems not to be needed anymore, since there is a new parser class. /work/users/adrian/kde33/kdegraphics3/ , if you want to have a look. I'll have a look... Created attachment 24191 [details]
kpdf-CESA-2004-007.diff
Adrian,
this is the kpdf patch.
Karl, I submitted packages for 9.0, 9.1, and STABLE patchinfo file for box: /work/src/done/PATCHINFO/pdftohtml.patch.box Vladimir, could you submit new packages? The fix for xpdf is attached. We can create patchinfos then. Packages for 8.1, 8.2 and 9.0 are submitted. So I guess maintained is noit affected and so is SL 9.1. I will submit patchinfos. Created attachment 24366 [details]
patchinfo file for box
...
Please tell suse-dist to build packages now. dirk, there is no public disclosure date yet for it, but I am trying to get one. coolo said to cc me for the KDE side of the problem. patchinfo files submitted. The only one missing is kpdf AFAIK. coordinated release date is 12th Oct. 1400 UTC CVE id ? none so far... Cups is affected either. The internal and default filter "pdftops" is a stripped xpdf version and the patch is working in latest version. Sorry for the late response. pdftops in cups needs: /work/SRC/old-versions/8.1/UL/all/xpdf/xpdf-overflow.patch /work/SRC/old-versions/8.1/UL/all/xpdf/xpdf-CESA-2004-007.diff replace filename ending .cc by .cxx Created attachment 24854 [details]
New patch for the issues described in advisory plus a few more I found.
...
Thx! xpdf packages and patchinfo are submited. Thank you! Karl, new pdftohtml package submitted CAN-2004-0888: Multiple integer overflow issues affecting xpdf-2.0 and xpdf-3.0 and things like cups which have embedded versions of xpdf-0*. These can result in writing an arbitrary byte to an attacker controlled location which probably could lead to arbitrary code execution. CAN-2004:0889: Multiple integer overflow issues affecting xpdf-3.0 only. These can result in DoS or possibly arbitrary code execution. Infinite loop logic error affecting xpdf-3.0 only. I don't think this is a security vulnerability for xpdf - now perhaps if this version of xpdf is embedded into something that parses pdf's automatically like CUPS (but CUPS embedds a version without this flaw). So I don't think this deserves a CVE name. I'm willing to be convinced otherwise though. when is the public disclosure date&time now? I've heard it was slipped what is the latest patch? CRD: 20. oct, 1400UTC ptach, as attached AFAIK new CRD will be 21. oct. 1400 UTC advisory released. only missing package is cups. Patchinfo for cups? /work/src/done/PATCHINFO/cups.patch.box /mounts/work/src/done/PATCHINFO/cups.patch.maintained Made cups patches (packages) for: UL1/SLES8/8.1, 8.2, 9.0, 9.1/SLES9/SLD, 9.2 Couldn't test older versions, as my test machine is currently broken (cpu fan broken). 9.2 patches seem to work. :-) Thx Klaus. cups packages approved |