GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Apr 07, 2007 12:26 am Post subject: [ GLSA 200704-06 ] Evince: Stack overflow in included gv cod |
|
|
Gentoo Linux Security Advisory
Title: Evince: Stack overflow in included gv code (GLSA 200704-06)
Severity: normal
Exploitable: remote
Date: April 06, 2007
Bug(s): #156573
ID: 200704-06
Synopsis
Evince improperly handles user-supplied data possibly allowing for the
execution of arbitrary code.
Background
Evince is a document viewer for multiple document formats, including
PostScript.
Affected Packages
Package: app-text/evince
Vulnerable: < 0.6.1-r3
Unaffected: >= 0.6.1-r3
Architectures: All supported architectures
Description
Evince includes code from GNU gv that does not properly boundary check
user-supplied data before copying it into process buffers.
Impact
An attacker could entice a user to open a specially crafted PostScript
document with Evince and possibly execute arbitrary code with the
rights of the user running Evince.
Workaround
There is no known workaround at this time.
Resolution
All Evince users should upgrade to the latest version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/evince-0.6.1-r3" |
References
CVE-2006-5864
GLSA-200611-20
Last edited by GLSA on Thu Feb 27, 2014 4:25 am; edited 7 times in total |
|