Gentoo Logo

PDFjam: Multiple vulnerabilities

Content:

1.  Gentoo Linux Security Advisory

Version Information

Advisory Reference GLSA 200903-05 / pdfjam
Release Date March 07, 2009
Latest Revision March 07, 2009: 01
Impact normal
Exploitable local
Package Vulnerable versions Unaffected versions Architecture(s)
app-text/pdfjam < 1.20-r1 >= 1.20-r1 All supported architectures

Related bugreports: #252734

Synopsis

Multiple vulnerabilities in the PDFjam scripts allow for local privilege escalation.

2.  Impact Information

Background

PDFjam is a small collection of shell scripts to edit PDF documents, including pdfnup, pdfjoin and pdf90.

Description

  • Martin Vaeth reported multiple untrusted search path vulnerabilities (CVE-2008-5843).
  • Marcus Meissner of the SUSE Security Team reported that temporary files are created with a predictable name (CVE-2008-5743).

Impact

A local attacker could place a specially crafted Python module in the current working directory or the /var/tmp directory, and entice a user to run the PDFjam scripts, leading to the execution of arbitrary code with the privileges of the user running the application. A local attacker could also leverage symlink attacks to overwrite arbitrary files.

3.  Resolution Information

Workaround

There is no known workaround at this time.

Resolution

All PDFjam users should upgrade to the latest version:

Code Listing 3.1: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/pdfjam-1.20-r1"

4.  References



Print

Page updated March 07, 2009

Summary: This is a Gentoo Linux Security Advisory

Security Team
Contact Address

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.