Joined: 12 May 2004
|Posted: Sat Apr 07, 2007 12:26 am Post subject: [ GLSA 200704-06 ] Evince: Stack overflow in included gv cod
|Gentoo Linux Security Advisory
Title: Evince: Stack overflow in included gv code (GLSA 200704-06)
Date: April 06, 2007
Evince improperly handles user-supplied data possibly allowing for the
execution of arbitrary code.
Evince is a document viewer for multiple document formats, including
Vulnerable: < 0.6.1-r3
Unaffected: >= 0.6.1-r3
Architectures: All supported architectures
Evince includes code from GNU gv that does not properly boundary check
user-supplied data before copying it into process buffers.
An attacker could entice a user to open a specially crafted PostScript
document with Evince and possibly execute arbitrary code with the
rights of the user running Evince.
There is no known workaround at this time.
All Evince users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/evince-0.6.1-r3"
Last edited by GLSA on Thu Feb 27, 2014 4:25 am; edited 7 times in total