>> rPath Linux Security Update Fixes Multiple Package Command Execution
Title : rPath Linux Security Update Fixes Multiple Package Command Execution VUPEN ID : VUPEN/ADV-2007-4030 CVE ID : CVE-2007-4352 - CVE-2007-5392 - CVE-2007-5393
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-28
Technical Description
Multiple vulnerabilities have been identified in rPath Linux, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. These issues are caused by errors in cups, poppler and tetex. For additional information, see : VUPEN/ADV-2007-3775 - VUPEN/ADV-2007-3779 - VUPEN/ADV-2007-3786
Upgrade the affected packages :
cups=conary.rpath.com at rpl:1/1.1.23-14.4-1
poppler=conary.rpath.com at rpl:1/0.4.5-1.3-1
tetex=conary.rpath.com at rpl:1/2.0.2-28.8-1
tetex-afm=conary.rpath.com at rpl:1/2.0.2-28.8-1
tetex-dvips=conary.rpath.com at rpl:1/2.0.2-28.8-1
tetex-fonts=conary.rpath.com at rpl:1/2.0.2-28.8-1
tetex-latex=conary.rpath.com at rpl:1/2.0.2-28.8-1
tetex-xdvi=conary.rpath.com at rpl:1/2.0.2-28.8-1 References