Gentoo Archives: gentoo-announce

From: Raphael Marichez <falco@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200703-24 ] mgv: Stack overflow in included gv code
Date: Tue, 27 Mar 2007 00:01:56
Message-Id: 20070326200520.GI25824@falco.falcal.net
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200703-24
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: mgv: Stack overflow in included gv code
9 Date: March 26, 2007
10 Bugs: #154645
11 ID: 200703-24
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 mgv improperly handles user-supplied data possibly allowing for the
19 execution of arbitrary code.
20
21 Background
22 ==========
23
24 mgv is a Postscript viewer with a Motif interface, based on Ghostview
25 and GNU gv.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 app-text/mgv <= 3.1.5 Vulnerable!
34 -------------------------------------------------------------------
35 NOTE: Certain packages are still vulnerable. Users should migrate
36 to another package if one is available or wait for the
37 existing packages to be marked stable by their
38 architecture maintainers.
39
40 Description
41 ===========
42
43 mgv includes code from gv that does not properly boundary check
44 user-supplied data before copying it into process buffers.
45
46 Impact
47 ======
48
49 An attacker could entice a user to open a specially crafted Postscript
50 document with mgv and possibly execute arbitrary code with the rights
51 of the user running mgv.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 mgv is currently unmaintained, and the mgv website no longer exists. As
62 such, the mgv package has been masked in Portage. We recommend that
63 users select an alternate Postscript viewer such as ghostview or
64 GSview, and unmerge mgv:
65
66 # emerge --unmerge "app-text/mgv"
67
68 References
69 ==========
70
71 [ 1 ] CVE-2006-5864
72 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5864
73 [ 2 ] GLSA 200611-20
74 http://www.gentoo.org/security/en/glsa/glsa-200611-20.xml
75
76 Availability
77 ============
78
79 This GLSA and any updates to it are available for viewing at
80 the Gentoo Security Website:
81
82 http://security.gentoo.org/glsa/glsa-200703-24.xml
83
84 Concerns?
85 =========
86
87 Security is a primary focus of Gentoo Linux and ensuring the
88 confidentiality and security of our users machines is of utmost
89 importance to us. Any security concerns should be addressed to
90 security@g.o or alternatively, you may file a bug at
91 http://bugs.gentoo.org.
92
93 License
94 =======
95
96 Copyright 2007 Gentoo Foundation, Inc; referenced text
97 belongs to its owner(s).
98
99 The contents of this document are licensed under the
100 Creative Commons - Attribution / Share Alike license.
101
102 http://creativecommons.org/licenses/by-sa/2.5