BMV PostScript File Handling Integer Overflow Vulnerability
BID:15153
Info
BMV PostScript File Handling Integer Overflow Vulnerability
| Bugtraq ID: | 15153 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3278 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2005 12:00AM |
| Updated: | May 31 2006 07:17PM |
| Credit: | Discovery is credited to felinemenace. |
| Vulnerable: |
Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 BMV BMV 1.2 |
| Not Vulnerable: | |
Discussion
BMV PostScript File Handling Integer Overflow Vulnerability
BMV is prone to an integer-overflow vulnerability.
This issue arises when the application handles a malformed PostScript file.
A successful attack may result in arbitrary code execution leading to unauthorized access. Reports indicate that on some distributions, BMV is installed setuid root by default. This may allow an attacker to gain superuser privileges by exploiting this issue.
BMV is prone to an integer-overflow vulnerability.
This issue arises when the application handles a malformed PostScript file.
A successful attack may result in arbitrary code execution leading to unauthorized access. Reports indicate that on some distributions, BMV is installed setuid root by default. This may allow an attacker to gain superuser privileges by exploiting this issue.
Exploit / POC
BMV PostScript File Handling Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
BMV PostScript File Handling Integer Overflow Vulnerability
Solution:
Debian advisory DSA-981-1 is available to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
BMV BMV 1.2
Solution:
Debian advisory DSA-981-1 is available to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
BMV BMV 1.2
-
Debian bmv_1.2-14.3_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/b/bmv/bmv_1.2-14.3_i386.d eb -
Debian bmv_1.2-17sarge1_i386.deb
Debian GNU/Linux 3.1 (sarge)
http://security.debian.org/pool/updates/main/b/bmv/bmv_1.2-17sarge1_i3 86.deb
References
BMV PostScript File Handling Integer Overflow Vulnerability
References:
References:
- bmv 1.2-17 (felinemenace)
- DSA-981-1 bmv -- integer overflow (Debian)