Gentoo Archives: gentoo-announce

From: Raphael Marichez <falco@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200608-22 ] fbida: Arbitrary command execution
Date: Wed, 23 Aug 2006 20:02:35
Message-Id: 200608232145.17414@msgid.falco.bz
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200608-22
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: fbida: Arbitrary command execution
9 Date: August 23, 2006
10 Bugs: #141684
11 ID: 200608-22
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 The fbgs script provided by fbida allows the execution of arbitrary
19 code.
20
21 Background
22 ==========
23
24 fbida is a collection of image viewers and editors for the framebuffer
25 console and X11. fbgs is a PostScript and PDF viewer for the linux
26 framebuffer console.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 media-gfx/fbida < 2.03-r4 >= 2.03-r4
35
36 Description
37 ===========
38
39 Toth Andras has discovered a typographic mistake in the "fbgs" script,
40 shipped with fbida if the "fbcon" and "pdf" USE flags are both enabled.
41 This script runs "gs" without the -dSAFER option, thus allowing a
42 PostScript file to execute, delete or create any kind of file on the
43 system.
44
45 Impact
46 ======
47
48 A remote attacker can entice a vulnerable user to view a malicious
49 PostScript or PDF file with fbgs, which may result with the execution
50 of arbitrary code.
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time.
56
57 Resolution
58 ==========
59
60 All fbida users with the "fbcon" and "pdf" USE flags both enabled
61 should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=media-gfx/fbida-2.03-r4"
65
66 References
67 ==========
68
69 [ 1 ] CVE-2006-3119
70 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3119
71
72 Availability
73 ============
74
75 This GLSA and any updates to it are available for viewing at
76 the Gentoo Security Website:
77
78 http://security.gentoo.org/glsa/glsa-200608-22.xml
79
80 Concerns?
81 =========
82
83 Security is a primary focus of Gentoo Linux and ensuring the
84 confidentiality and security of our users machines is of utmost
85 importance to us. Any security concerns should be addressed to
86 security@g.o or alternatively, you may file a bug at
87 http://bugs.gentoo.org.
88
89 License
90 =======
91
92 Copyright 2006 Gentoo Foundation, Inc; referenced text
93 belongs to its owner(s).
94
95 The contents of this document are licensed under the
96 Creative Commons - Attribution / Share Alike license.
97
98 http://creativecommons.org/licenses/by-sa/2.5