In association with heise online

21 November 2006, 14:52

Updates close holes in GNU gv

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

A vulnerability in the GNU tool gv, used for displaying PostScript and PDF documents, threatens system security. The opening of a document with overlong comments creates a buffer overflow in the ps_gettext() function, the bug advisory reports. That in turn could be exploited to plant malicious code and execute it with the user's rights. Files prepared in this way can make their way onto computers as mail attachments or as downloads from a website. Version 3.6.2 and earlier are affected. No official update has been released. Several Linux distributors like Debian and Mandriva have already released packages without the bug.

See also:


Print Version | Send by email | Permalink:

  • July's Community Calendar

The H Open

The H Security

The H Developer

The H Internet Toolkit