SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#352825

GNU gv buffer overflow vulnerability

Overview

A buffer overflow vulnerability exists in the GNU gv viewer application. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code, or cause a denial-of-service condition.

I. Description

From the GNU gv website:

    GNU gv allows to view and navigate through PostScript and PDF documents on an X display by providing a user interface for the ghostscript interpreter.
    gv is a improved derivation of Timothy O. Theisen's Ghostview developed by Johannes Plass.

A buffer overflow vulnerability exists in the GNU gv viewer. An attacker may be able to trigger the overflow by convincing a user to open a specially-crafted PostScript file.

Note that GNU gv is maintained and packaged by many vendors. Please see the systems affected portion of this document for a list of vendors who distribute GNU gv.

II. Impact

A remote, unauthenticated attacker may be able to execute code with the privileges of the user running GNU gv.

III. Solution

Upgrade

Apply an upgrade. See the systems affected portion of this document for information about specific vendors.

Do not execute GNU gv with root privileges

Using a non-privileged user account to launch GNU gv may mitigate the impact of this vulnerability.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Unknown28-Nov-2006
Conectiva Inc.Unknown28-Nov-2006
Cray Inc.Unknown28-Nov-2006
Debian GNU/LinuxVulnerable28-Nov-2006
EMC, Inc. (formerly Data General Corporation)Unknown28-Nov-2006
Engarde Secure LinuxUnknown28-Nov-2006
F5 Networks, Inc.Unknown28-Nov-2006
Fedora ProjectUnknown28-Nov-2006
FreeBSD, Inc.Unknown28-Nov-2006
FujitsuUnknown28-Nov-2006
Gentoo LinuxVulnerable29-Nov-2006
Hewlett-Packard CompanyUnknown28-Nov-2006
HitachiUnknown28-Nov-2006
IBM CorporationUnknown28-Nov-2006
IBM Corporation (zseries)Unknown28-Nov-2006
IBM eServerUnknown28-Nov-2006
Immunix Communications, Inc.Unknown28-Nov-2006
Ingrian Networks, Inc.Unknown28-Nov-2006
Juniper Networks, Inc.Not Vulnerable28-Nov-2006
Mandriva, Inc.Unknown28-Nov-2006
Microsoft CorporationNot Vulnerable28-Nov-2006
MontaVista Software, Inc.Unknown28-Nov-2006
NEC CorporationUnknown28-Nov-2006
NetBSDNot Vulnerable29-Nov-2006
NokiaUnknown28-Nov-2006
Novell, Inc.Unknown28-Nov-2006
OpenBSDUnknown28-Nov-2006
Openwall GNU/*/LinuxNot Vulnerable1-Dec-2006
QNX, Software Systems, Inc.Unknown28-Nov-2006
Red Hat, Inc.Unknown28-Nov-2006
Silicon Graphics, Inc.Unknown28-Nov-2006
Slackware Linux Inc.Unknown28-Nov-2006
Sony CorporationUnknown28-Nov-2006
Sun Microsystems, Inc.Unknown28-Nov-2006
SUSE LinuxUnknown28-Nov-2006
The SCO GroupUnknown28-Nov-2006
Trustix Secure LinuxUnknown28-Nov-2006
TurbolinuxUnknown28-Nov-2006
UbuntuUnknown28-Nov-2006
UnisysUnknown28-Nov-2006
Wind River Systems, Inc.Unknown28-Nov-2006

References


http://secunia.com/advisories/22787/
http://secunia.com/advisories/23018/
http://secunia.com/advisories/23006/

Credit

This vulnerability was publicly reported by Renaud Lifchitz.

This document was written by Ryan Giobbi.

Other Information

Date Public:2006-11-09
Date First Published:2006-11-28
Date Last Updated:2006-12-01
CERT Advisory: 
CVE-ID(s):CVE-2006-5864
NVD-ID(s):CVE-2006-5864
US-CERT Technical Alerts: 
Metric:0.10
Document Revision:34

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader