exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

kde-kghostview.txt

kde-kghostview.txt
Posted Oct 14, 2002
Site kde.org

KDE Security Advisory - A buffer overflow reported by iDEFENSE to exist in gv also affects Kghostview. Abuse of this vulnerability can be done trough a specially crafted .ps file and may lead to arbitrary code execution. This affects all Kghostview versions released between KDE 1.1 and KDE 3.0.3a. The KDE developers fixed the vulnerability in the kdegraphics-3.0.4 package, which is available here.

tags | overflow, arbitrary, code execution
SHA-256 | 969c73ad52801821a3db29e61dd2734a11764b7c84f517d695c246b2bf8f4cce

kde-kghostview.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

KDE Security Advisory: KGhostview Arbitary Code Execution
Original Release Date: 2002-10-08
URL: http://www.kde.org/info/security/advisory-20021008-1.txt

0. References

cve.mitre.org: CAN-2002-0838
BUGTRAQ:20020926 iDEFENSE Security Advisory 09.26.2002:
Exploitable Buffer Overflow in gv
http://marc.theaimsgroup.com/?l=bugtraq&m=103305615613319&w=2

1. Systems affected:

KGhostView of any KDE release between KDE 1.1 and KDE 3.0.3a

2. Overview:

KGhostview includes a DSC 3.0 parser from GSview, which is vulnerable
to a buffer overflow while parsing a specially crafted .ps input
file. It also contains code from gv 3.5.x which is vulnerable to another
buffer overflow triggered by malformed postscript or Adobe pdf files.

3. Impact:

Viewing certain Postscript or PDF files can result in the execution of
arbitary code placed in the file and as a result opens possibilities for
any remote manipulation under the local user account.

4. Solution:

Apply the patch listed in section 5 to kdegraphics/kghostview, or update
to KDE 3.0.4.

kdegraphics-3.0.4 can be downloaded from

http://download.kde.org/stable/3.0.4 :

6065219c825102c843ba582c4a520cac kdegraphics-3.0.4.tar.bz2

5. Patch:

A patch for KDE 3.0.3 is available from

ftp://ftp.kde.org/pub/kde/security_patches :
9e33962406ac123e4fbdab20b4123ccf post-3.0.3-kdegraphics-kghostview.diff

A patch for KDE 2.2.2 is available from

ftp://ftp.kde.org/pub/kde/security_patches :
62a1178c6a1730cbab98bbc825adafe9 post-2.2.2-kdegraphics-kghostview.diff
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE9pDXDvsXr+iuy1UoRAvfZAKCxyetx90FfIDpTeq028QUEfXM6TwCgjOMl
pLaRHeMmf/kUDz9HwpOW6fk=
=w/u0
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    29 Files
  • 21
    Aug 21st
    42 Files
  • 22
    Aug 22nd
    26 Files
  • 23
    Aug 23rd
    25 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    21 Files
  • 27
    Aug 27th
    28 Files
  • 28
    Aug 28th
    15 Files
  • 29
    Aug 29th
    41 Files
  • 30
    Aug 30th
    13 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close