Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

GV Malformed PDF/PS File Buffer Overflow Vulnerability

Solution:
Red Hat has released an advisory. Updates for ggv are available. See the referenced advisory for further details.

The KDE Project has made a patch available for affected versions of kdegraphics/kghostview. Additionally, the KDE Project has identified the 3.0.4 series as being fixed against this vulnerability.

Gentoo Linux has released an advisory for ggv. Users who have installed app-text/ggv-1.99.90 and earlier are urged to update their systems by issuing the following commands:

emerge rsync
emerge ggv
emerge clean

Debian has released a new advisory DSA 179-1. Fixes for gnome-gv 0.82 and gnome-gv 1.1.96 are available. Debian GNU/Linux 3.0 alias woody also ships with KDE 2.2.2, which includes a vulnerable kghostview in the KDE-Graphics package.

Conectiva Linux has released an advisory. Information about obtaining and installing fixes for gv and kdegraphics can be found in the referenced advisory.

RedHat has released an advisory, RHSA-2002:220-40, that contains many fixes. Information about obtaining and applying fixes are available in the referenced advisory.

Red Hat has released an updated RHSA-2002-207 advisory containing new fixes to address this issue in Red Hat 7.1 pseries and iseries. Please see the attached web reference for further information.

Gentoo has released an advisory for gv that includes fixes. Fixes may be applied with the following commands:
emerge sync
emerge -pv ">=app-text/gv-3.5.8-r4"
emerge ">=app-text/gv-3.5.8-r4"

Fixes:


ggv ggv 0.82

ggv ggv 1.0.2

ggv ggv 1.1.96

ggv ggv 1.99.90

KDE KDE 2.0

KDE KDE 2.0.1

KDE KDE 2.1

KDE KDE 2.1.1

KDE KDE 2.1.2

KDE KDE 2.2

KDE KDE 2.2.1

KDE KDE 2.2.2

KDE KDE 3.0

KDE KDE 3.0.1

KDE KDE 3.0.2

KDE KDE 3.0.3 a

KDE KDE 3.0.3

gv gv 3.5.8







 

Privacy Statement
Copyright 2008, SecurityFocus