CVE-2006-5864
evince
EPSS 14.8%
描述
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.
如何修補 CVE-2006-5864
要修補 CVE-2006-5864,請將受影響套件升級到下列已修補版本。
- Debian/evince—升級至 0.4.0-3 或更新版本
- —升級至 0.1.5-2sarge1 或更新版本
- —升級至 1:3.6.2-3 或更新版本
- —升級至 1:3.6.1-10sarge2 或更新版本
- —升級至 1:3.6.1-10sarge1 或更新版本
- —升級至 1:3.6.1-10sarge2 或更新版本
CVE-2006-5864 正在被利用嗎?
中等 — EPSS 為 14.8%,可持續追蹤但非最高優先。
受影響套件(6)
- from 0, < 0.4.0-3
- from 0, < 0.1.5-2sarge1
- from 0, < 1:3.6.2-3
- from 0, < 1:3.6.1-10sarge2
- from 0, < 1:3.6.1-10sarge1
- from 0, < 1:3.6.1-10sarge2