Bug 215136

Summary: CVE-2006-5864: gv <= 3.6.2 stack-based buffer overflow
Product: [Fedora] Fedora Reporter: Ville Skyttä <scop>
Component: gvAssignee: Orion Poplawski <orion>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: medium    
Version: 6CC: extras-qa, fedora-security-list, michal
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-5864
Whiteboard:
Fixed In Version: 3.6.2-2 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-12-05 19:42:28 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 215265    

Description Ville Skyttä 2006-11-11 10:46:46 UTC
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-5864

"Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv
3.6.2, and possibly earlier versions, allows user-assisted attackers to execute
arbitrary code via a PostScript (PS) file with certain headers that contain long
comments, as demonstrated using the DocumentMedia header."

Comment 2 Michal Jaegermann 2006-12-04 17:09:44 UTC
Mandriva Linux Security Advisory, MDKSA-2006:214-1, says the following:

"The patch used in the previous update still left the possibility of
 causing X to consume unusual amounts of memory if gv is used to view a
 carefully crafted image designed to exploit CVE-2006-5864. This update
 uses an improved patch to address this issue."

For patches see, for example, gv-3.6.1-4.3.20060mdk.src.rpm

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5864

Comment 3 Orion Poplawski 2006-12-05 19:42:28 UTC
Thanks for the references.  Fixed in 3.6.2-2.

Comment 4 Ville Skyttä 2006-12-06 17:39:42 UTC
For info for people interested in older distros: the patch has been applied in
Extras for FC5+ only, not FC4 at the moment.