In association with heise online

21 November 2006, 15:52

Updates close holes in GNU gv

A vulnerability in the GNU tool gv, used for displaying PostScript and PDF documents, threatens system security. The opening of a document with overlong comments creates a buffer overflow in the ps_gettext() function, the bug advisory reports. That in turn could be exploited to plant malicious code and execute it with the user's rights. Files prepared in this way can make their way onto computers as mail attachments or as downloads from a website. Version 3.6.2 and earlier are affected. No official update has been released. Several Linux distributors like Debian and Mandriva have already released packages without the bug.

See also:

(ehe)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit







The H open source

The H Security

The H Internet Toolkit