GV Postscript and PDF Viewer Multiple Remote Buffer Overflow Vulnerabilities
BID:10944
Info
GV Postscript and PDF Viewer Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 10944 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2004 12:00AM |
| Updated: | Aug 14 2004 12:00AM |
| Credit: | Discovery is credited to sean <[email protected]>. |
| Vulnerable: |
gv gv 3.5.8 gv gv 3.5.3 gv gv 3.5.2 gv gv 3.4.12 gv gv 3.4.3 gv gv 3.4.2 gv gv 3.2.4 gv gv 3.1.6 gv gv 3.1.4 gv gv 3.0.4 gv gv 3.0 .0 gv gv 2.9.4 gv gv 2.7.6 gv gv 2.7 b5 gv gv 2.7 b4 gv gv 2.7 b3 gv gv 2.7 b2 gv gv 2.7 b1 |
| Not Vulnerable: | |
Discussion
GV Postscript and PDF Viewer Multiple Remote Buffer Overflow Vulnerabilities
gv is reported prone to multiple remote buffer overflow vulnerabilities. These issues exist due to insufficient checking performed by the application on file headers for PostScript and PDF documents.
These vulnerabilities exist in the 'psscan' function of the 'ps.c' file. The vulnerabilities include multiple stack and heap based buffer overflows. A number of the stack overflows have been specified, however, there are also a number of unspecified heap overflows.
Successful exploitation of these issues may result in an attacker executing arbitrary code on a vulnerable computer to gain unauthorized access. This would occur in the context of the vulnerable application.
It should be noted that applications such as Web browsers may use the software as an automatic handler for PostScript and PDF files.
gv is reported prone to multiple remote buffer overflow vulnerabilities. These issues exist due to insufficient checking performed by the application on file headers for PostScript and PDF documents.
These vulnerabilities exist in the 'psscan' function of the 'ps.c' file. The vulnerabilities include multiple stack and heap based buffer overflows. A number of the stack overflows have been specified, however, there are also a number of unspecified heap overflows.
Successful exploitation of these issues may result in an attacker executing arbitrary code on a vulnerable computer to gain unauthorized access. This would occur in the context of the vulnerable application.
It should be noted that applications such as Web browsers may use the software as an automatic handler for PostScript and PDF files.
Exploit / POC
GV Postscript and PDF Viewer Multiple Remote Buffer Overflow Vulnerabilities
Exploit code is available:
Exploit code is available:
Solution / Fix
GV Postscript and PDF Viewer Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GV Postscript and PDF Viewer Multiple Remote Buffer Overflow Vulnerabilities
References:
References: