GV Malformed PDF/PS File Buffer Overflow Vulnerability

BID:5808

Info

GV Malformed PDF/PS File Buffer Overflow Vulnerability

Bugtraq ID: 5808
Class: Boundary Condition Error
CVE: CVE-2002-0838
Remote: Yes
Local: Yes
Published: Sep 26 2002 12:00AM
Updated: Jul 11 2009 05:06PM
Credit: Vulnerability discovery credited to zen parse <[email protected]>.
Vulnerable: KDE KDE 3.0.3 a
KDE KDE 3.0.3
+ Conectiva Linux Enterprise Edition 1.0
+ FreeBSD FreeBSD 4.7 -STABLE
+ FreeBSD FreeBSD 4.7 -STABLE
+ Mandriva Linux Mandrake 9.0
+ Mandriva Linux Mandrake 9.0
KDE KDE 3.0.2
+ Mandriva Linux Mandrake 8.2
KDE KDE 3.0.1
KDE KDE 3.0
KDE KDE 2.2.2
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.1
+ Redhat Advanced Workstation for the Itanium Processor 2.1
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1
+ Redhat Enterprise Linux WS 2.1
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 i386
+ Redhat Linux Advanced Work Station 2.1
+ Sun Linux 5.0.7
+ Sun Linux 5.0.7
+ Sun Linux 5.0.6
+ Sun Linux 5.0.6
+ Sun Linux 5.0.5
+ Sun Linux 5.0.5
KDE KDE 2.2.1
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Caldera OpenLinux Workstation 3.1
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
KDE KDE 2.2
KDE KDE 2.1.2
KDE KDE 2.1.1
KDE KDE 2.1
KDE KDE 2.0.1
KDE KDE 2.0
KDE KDE 1.2
- SuSE Linux 6.4
KDE KDE 1.1.2
+ Caldera OpenLinux 2.3
+ Mandriva Linux Mandrake 7.0
KDE KDE 1.1.1
KDE KDE 1.1
gv gv 3.5.8
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.2
- Redhat Linux 7.3
+ Redhat Linux 7.1 pseries
+ Redhat Linux 7.1 iseries
+ Sun Linux 5.0
gv gv 3.5.3
gv gv 3.5.2
gv gv 3.4.12
gv gv 3.4.3
gv gv 3.4.2
gv gv 3.2.4
gv gv 3.1.6
gv gv 3.1.4
gv gv 3.0.4
gv gv 3.0 .0
gv gv 2.9.4
gv gv 2.7.6
gv gv 2.7 b5
gv gv 2.7 b4
gv gv 2.7 b3
gv gv 2.7 b2
gv gv 2.7 b1
GhostView GhostView 1.5
GhostView GhostView 1.4.1
GhostView GhostView 1.4
GhostView GhostView 1.3
ggv ggv 1.99.90
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.2
+ Gentoo Linux 1.2
ggv ggv 1.1.96
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Debian Linux 3.0
ggv ggv 1.0.2
ggv ggv 0.82
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
+ Debian Linux 2.2
Not Vulnerable: KDE KDE 3.0.4
+ Gentoo Linux 1.4 _rc1
+ Gentoo Linux 1.2
+ Gentoo Linux 1.2

Discussion

GV Malformed PDF/PS File Buffer Overflow Vulnerability

gv is a freely available, open source Portable Document Format (PDF) and PostScript (PS) viewing utility. It is available for Unix and Linux operating systems.

It has been reported that an insecure sscanf() function exists in gv. Due to this function, an attacker may be able to put malicious code in the %%PageOrder: portion of a file. When this malicious file is opened with gv, the code would be executed in the security context of the user opening the file.

Exploit / POC

GV Malformed PDF/PS File Buffer Overflow Vulnerability

Exploit contributed by zen parse &lt;[email protected]&gt;. Exploit code has also been provided by priest priest &lt;[email protected]&gt;, and &lt;[email protected]&gt;.

Solution / Fix

GV Malformed PDF/PS File Buffer Overflow Vulnerability

Solution:
Red Hat has released an advisory. Updates for ggv are available. See the referenced advisory for further details.

The KDE Project has made a patch available for affected versions of kdegraphics/kghostview. Additionally, the KDE Project has identified the 3.0.4 series as being fixed against this vulnerability.

Gentoo Linux has released an advisory for ggv. Users who have installed app-text/ggv-1.99.90 and earlier are urged to update their systems by issuing the following commands:

emerge rsync
emerge ggv
emerge clean

Debian has released a new advisory DSA 179-1. Fixes for gnome-gv 0.82 and gnome-gv 1.1.96 are available. Debian GNU/Linux 3.0 alias woody also ships with KDE 2.2.2, which includes a vulnerable kghostview in the KDE-Graphics package.

Conectiva Linux has released an advisory. Information about obtaining and installing fixes for gv and kdegraphics can be found in the referenced advisory.

RedHat has released an advisory, RHSA-2002:220-40, that contains many fixes. Information about obtaining and applying fixes are available in the referenced advisory.

Red Hat has released an updated RHSA-2002-207 advisory containing new fixes to address this issue in Red Hat 7.1 pseries and iseries. Please see the attached web reference for further information.

Gentoo has released an advisory for gv that includes fixes. Fixes may be applied with the following commands:
emerge sync
emerge -pv ">=app-text/gv-3.5.8-r4"
emerge ">=app-text/gv-3.5.8-r4"

Fixes:


ggv ggv 0.82

ggv ggv 1.0.2

ggv ggv 1.1.96

ggv ggv 1.99.90

KDE KDE 2.0

KDE KDE 2.0.1

KDE KDE 2.1

KDE KDE 2.1.1

KDE KDE 2.1.2

KDE KDE 2.2

KDE KDE 2.2.1

KDE KDE 2.2.2

KDE KDE 3.0

KDE KDE 3.0.1

KDE KDE 3.0.2

KDE KDE 3.0.3 a

KDE KDE 3.0.3

gv gv 3.5.8

References

GV Malformed PDF/PS File Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report