RHEL 2.1 : netpbm (RHSA-2003:061)

high Nessus Plugin ID 12367

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

Updated NetPBM packages are available that fix a number of vulnerabilities in the netpbm libraries.

The netpbm package contains a library of functions that support programs for handling various graphics file formats, including .pbm (portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable pixmaps), and others.

During an audit of the NetPBM library, Al Viro, Alan Cox, and Sebastian Krahmer found a number of bugs that are potentially exploitable. These bugs could be exploited by creating a carefully crafted image in such a way that it executes arbitrary code when it is processed by either an application from the netpbm-progs package or an application that uses the vulnerable netpbm library.

One way that an attacker could exploit these vulnerabilities would be to submit a carefully crafted image to be printed, as the LPRng print spooler used by default in Red Hat Linux Advanced Products releases uses netpbm utilities to parse various types of image files.

Users are advised to upgrade to the updated packages, which contain patches that correct these vulnerabilities.

Solution

Update the affected netpbm, netpbm-devel and / or netpbm-progs packages.

See Also

https://access.redhat.com/security/cve/cve-2003-0146

https://access.redhat.com/errata/RHSA-2003:061

Plugin Details

Severity: High

ID: 12367

File Name: redhat-RHSA-2003-061.nasl

Version: 1.26

Type: local

Agent: unix

Published: 7/6/2004

Updated: 1/14/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:netpbm, p-cpe:/a:redhat:enterprise_linux:netpbm-devel, p-cpe:/a:redhat:enterprise_linux:netpbm-progs, cpe:/o:redhat:enterprise_linux:2.1

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 3/31/2003

Vulnerability Publication Date: 3/31/2003

Reference Information

CVE: CVE-2003-0146

RHSA: 2003:061