Stack-based buffer overflow in the ps_gettext function in ps.c for...
Vulnerability Description
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-5864
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30153
- http://www.debian.org/security/2006/dsa-1214
- http://secunia.com/advisories/23018
- http://www.vupen.com/english/advisories/2006/4424
- http://secunia.com/advisories/22932
- https://www.exploit-db.com/exploits/2858
- http://secunia.com/advisories/23353
- http://secunia.com/advisories/23306
- http://secunia.com/advisories/23266
- http://secunia.com/advisories/23579
- http://secunia.com/advisories/24787
- http://www.novell.com/linux/security/advisories/2006_26_sr.html
- http://www.novell.com/linux/security/advisories/2006_28_sr.html
- http://secunia.com/advisories/23409
- http://security.gentoo.org/glsa/glsa-200704-06.xml
- http://security.gentoo.org/glsa/glsa-200703-24.xml
- http://www.ubuntu.com/usn/usn-390-2
- http://secunia.com/advisories/23335
- http://www.vupen.com/english/advisories/2006/4747
- http://www.kb.cert.org/vuls/id/352825
- http://www.securityfocus.com/archive/1/451057/100/0/threaded
- http://secunia.com/advisories/23111
- http://secunia.com/advisories/23183
- http://www.debian.org/security/2006/dsa-1243
- http://www.securityfocus.com/bid/20978
- http://security.gentoo.org/glsa/glsa-200611-20.xml
- http://www.securityfocus.com/archive/1/451422/100/200/threaded
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:214
- http://secunia.com/advisories/23006
- http://secunia.com/advisories/22787
- https://issues.rpath.com/browse/RPL-850
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30555
- http://secunia.com/advisories/23118
- http://secunia.com/advisories/24649
- http://www.novell.com/linux/security/advisories/2006_29_sr.html
- http://www.securityfocus.com/archive/1/452868/100/0/threaded
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:229
- http://www.ubuntu.com/usn/usn-390-3
- http://www.ubuntu.com/usn/usn-390-1
More from gnu
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.