GV Gunzipped Archive Malicious File Name Command Execution Vulnerability
BID:5840
Info
GV Gunzipped Archive Malicious File Name Command Execution Vulnerability
| Bugtraq ID: | 5840 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1569 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 01 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Vulnerability discovery credited to Marc Bevand <[email protected]>. |
| Vulnerable: |
gv gv 3.5.8 gv gv 3.5.3 gv gv 3.5.2 gv gv 3.4.12 gv gv 3.4.3 gv gv 3.4.2 gv gv 3.2.4 gv gv 3.1.6 gv gv 3.1.4 gv gv 3.0.4 gv gv 3.0 .0 gv gv 2.9.4 gv gv 2.7.6 gv gv 2.7 b5 gv gv 2.7 b4 gv gv 2.7 b3 gv gv 2.7 b2 gv gv 2.7 b1 GhostView GhostView 1.5 GhostView GhostView 1.4.1 GhostView GhostView 1.4 GhostView GhostView 1.3 |
| Not Vulnerable: | |
Discussion
GV Gunzipped Archive Malicious File Name Command Execution Vulnerability
gv is a freely available, open source Portable Document Format (PDF) and PostScript (PS) viewing utility. It is available for Unix and Linux operating systems.
Under some circumstances, gv does not properly handle file names. When a PostScript (PS) or Portable Document Format (PDF) file contained within a compressed archive such as a gzip archive is opened with gv, command execution may occur. A file name containing special characters such as backticks (`), quotes ("), and ampersands (&) will be interpretted as commands, and executed by gv.
gv is a freely available, open source Portable Document Format (PDF) and PostScript (PS) viewing utility. It is available for Unix and Linux operating systems.
Under some circumstances, gv does not properly handle file names. When a PostScript (PS) or Portable Document Format (PDF) file contained within a compressed archive such as a gzip archive is opened with gv, command execution may occur. A file name containing special characters such as backticks (`), quotes ("), and ampersands (&) will be interpretted as commands, and executed by gv.
Exploit / POC
GV Gunzipped Archive Malicious File Name Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GV Gunzipped Archive Malicious File Name Command Execution Vulnerability
Solution:
Gentoo Linux has released an advisory. Users who have installed app-text/gv-3.58-r1 are urged to upgrade by issuing the following commands:
emerge rsync
emerge gv
emerge clean
Solution:
Gentoo Linux has released an advisory. Users who have installed app-text/gv-3.58-r1 are urged to upgrade by issuing the following commands:
emerge rsync
emerge gv
emerge clean