National Cyber-Alert System
Vulnerability Summary for CVE-2006-5864
Original release date:11/11/2006
Last revised:09/05/2008
Source:
US-CERT/NIST
Overview
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.
Impact
CVSS Severity (version 2.0):
Impact Subscore:
6.4
Exploitability Subscore:
4.9
CVSS Version 2 Metrics:
Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Access Complexity: High
Authentication: Not required to exploit
Impact Type:Provides user account access, Allows partial confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service
Official Statement from Red Hat (09/07/2007)
Red Hat is aware of this issue and is tracking it via the following bug for Red Hat Enterprise Linux 2.1. This issue did not affect Red Hat Enterprise Linux 3 or 4.
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=215593
The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More
information regarding issue severity can be found here:
http://www.redhat.com/security/updates/classification/
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 2.1 which is in maintenance mode.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
US-CERT Vulnerability Note: VU#352825
Name: VU#352825
External Source: XF
Name: gnu-gv-buffer-overflow(30153)
External Source: BID
Name: 20978
External Source: BUGTRAQ
Name: 20061112 Re: GNU gv Stack Overflow Vulnerability
External Source: BUGTRAQ
Name: 20061109 GNU gv Stack Overflow Vulnerability
External Source: SUSE
Name: SUSE-SR:2006:026
External Source: VUPEN
Name: ADV-2006-4424
Type: Advisory
External Source: DEBIAN
Name: DSA-1214
External Source: GENTOO
Name: GLSA-200611-20
External Source: SECUNIA
Name: 23118
External Source: SECUNIA
Name: 23018
External Source: SECUNIA
Name: 23006
External Source: SECUNIA
Name: 22787
Type: Advisory
External Source: MANDRIVA
Name: MDKSA-2006:214
External Source: CONFIRM
Name: https://issues.rpath.com/browse/RPL-850
External Source: XF
Name: evince-postscript-bo(30555)
External Source: UBUNTU
Name: USN-390-3
External Source: UBUNTU
Name: USN-390-2
External Source: UBUNTU
Name: USN-390-1
External Source: BUGTRAQ
Name: 20061128 evince buffer overflow exploit (gv)
External Source: SUSE
Name: SUSE-SR:2006:029
External Source: SUSE
Name: SUSE-SR:2006:028
External Source: MANDRIVA
Name: MDKSA-2006:229
External Source: MANDRIVA
Name: MDKSA-2006:214
External Source: VUPEN
Name: ADV-2006-4747
External Source: DEBIAN
Name: DSA-1243
External Source: GENTOO
Name: GLSA-200704-06
External Source: GENTOO
Name: GLSA-200703-24
External Source: SECUNIA
Name: 24787
External Source: SECUNIA
Name: 24649
External Source: SECUNIA
Name: 23579
External Source: SECUNIA
Name: 23409
External Source: SECUNIA
Name: 23353
External Source: SECUNIA
Name: 23335
External Source: SECUNIA
Name: 23306
External Source: SECUNIA
Name: 23266
External Source: SECUNIA
Name: 23183
External Source: SECUNIA
Name: 23111
External Source: SECUNIA
Name: 22932
External Source: MILW0RM
Name: 2858
External Source: MANDRIVA
Name: MDKSA-2006:229