USN-164-1: netpbm vulnerability

USN-164-1: netpbm vulnerability

 
 
Referenced CVEs: 
CAN-2005-2471
Description: 
=========================================================== Ubuntu Security Notice USN-164-1 August 11, 2005 netpbm-free vulnerability CAN-2005-2471 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog) Ubuntu 5.04 (Hoary Hedgehog) The following packages are affected: netpbm The problem can be corrected by upgrading the affected package to version 2:10.0-5ubuntu0.1 (for Ubuntu 4.10), or 2:10.0-8ubuntu0.1 (for Ubuntu 5.04). In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Max Vozeler discovered that the the "pstopnm" conversion tool did not use the -dSAFER option when calling ghostscript. This option prohibits file operations and calling commands within PostScript code. This flaw could be exploited by an attacker to execute arbitrary code if he tricked an user (or an automatic server) into processing a specially crafted PostScript document with pstopnm.