Executive Summary

Summary
Title teTeX vulnerability
Informations
Name USN-410-2 First vendor Publication 2007-01-25
Vendor Ubuntu Last vendor Modification 2007-01-25
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects the following Ubuntu releases:

Ubuntu 5.10

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 5.10:
tetex-bin 2.0.2-30ubuntu3.6

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

USN-410-1 fixed vulnerabilities in the poppler PDF loader library. This update provides the corresponding updates for a copy of this code in tetex-bin in Ubuntu 5.10. Versions of tetex-bin after Ubuntu 5.10 use poppler directly and do not need a separate update.

Original advisory details:

The poppler PDF loader library did not limit the recursion depth of
the page model tree. By tricking a user into opening a specially
crafter PDF file, this could be exploited to trigger an infinite loop
and eventually crash an application that uses this library.

Original Source

Url : http://www.ubuntu.com/usn/USN-410-2

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-20 Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 5
Os 12

OpenVAS Exploits

Date Description
2009-10-10 Name : SLES9: Security update for cups
File : nvt/sles9p5011363.nasl
2009-04-09 Name : Mandriva Update for koffice MDKSA-2007:018 (koffice)
File : nvt/gb_mandriva_MDKSA_2007_018.nasl
2009-04-09 Name : Mandriva Update for pdftohtml MDKSA-2007:019 (pdftohtml)
File : nvt/gb_mandriva_MDKSA_2007_019.nasl
2009-04-09 Name : Mandriva Update for poppler MDKSA-2007:020 (poppler)
File : nvt/gb_mandriva_MDKSA_2007_020.nasl
2009-04-09 Name : Mandriva Update for xpdf MDKSA-2007:021 (xpdf)
File : nvt/gb_mandriva_MDKSA_2007_021.nasl
2009-04-09 Name : Mandriva Update for tetex MDKSA-2007:022 (tetex)
File : nvt/gb_mandriva_MDKSA_2007_022.nasl
2009-04-09 Name : Mandriva Update for kdegraphics MDKSA-2007:024 (kdegraphics)
File : nvt/gb_mandriva_MDKSA_2007_024.nasl
2009-03-23 Name : Ubuntu Update for kdegraphics, koffice, poppler vulnerability USN-410-1
File : nvt/gb_ubuntu_USN_410_1.nasl
2009-03-23 Name : Ubuntu Update for tetex-bin vulnerability USN-410-2
File : nvt/gb_ubuntu_USN_410_2.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
32871 Multiple Products Adobe PDF Specification Invalid Tree Node DoS

32870 Multiple Products Adobe PDF Specification Malformed Catalog Dictionary DoS

Snort® IPS/IDS

Date Description
2014-01-10 Adobe Acrobat Reader PDF Catalog Handling denial of service attempt
RuleID : 17361 - Revision : 16 - Type : FILE-PDF

Nessus® Vulnerability Scanner

Date Description
2007-12-13 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_xpdf-tools-2474.nasl - Type : ACT_GATHER_INFO
2007-12-13 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_cups-2528.nasl - Type : ACT_GATHER_INFO
2007-12-13 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_poppler-2589.nasl - Type : ACT_GATHER_INFO
2007-12-13 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_kdegraphics3-pdf-2564.nasl - Type : ACT_GATHER_INFO
2007-11-10 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-410-2.nasl - Type : ACT_GATHER_INFO
2007-11-10 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-410-1.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_koffice-wordprocessing-2577.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_xpdf-tools-2472.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_xpdf-2473.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_poppler-2590.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_pdftohtml-2475.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_libextractor-2494.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_koffice-wordprocessing-2648.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_kdegraphics3-pdf-2565.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_gpdf-2596.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_cups-2527.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2007-018.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2007-024.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2007-022.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2007-021.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2007-020.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing a security update.
File : mandrake_MDKSA-2007-019.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-17 12:04:06
  • Multiple Updates
2013-05-11 00:55:34
  • Multiple Updates