Bug#723124: /usr/bin/pdfseparate: pdfseparate segfault based on filenames (possibly exploitable)

2013-09-16 Thread Pino Toscano
Hi, In data lunedì 16 settembre 2013 13:42:00, hai scritto: Package: poppler-utils Version: 0.22.5-2 Severity: normal File: /usr/bin/pdfseparate utils/pdfseparate.cc appears to invoke sprintf directly on user-passed data without cleaning or verifying it. bool extractPages (const char

Bug#723124: /usr/bin/pdfseparate: pdfseparate segfault based on filenames (possibly exploitable)

2013-09-16 Thread Daniel Kahn Gillmor
Package: poppler-utils Version: 0.22.5-2 Severity: normal File: /usr/bin/pdfseparate utils/pdfseparate.cc appears to invoke sprintf directly on user-passed data without cleaning or verifying it. bool extractPages (const char *srcFileName, const char *destFileName) { char pathName[1024]; /*