search menu icon-carat-right cmu-wordmark

CERT Coordination Center

gv contains buffer overflow in sscanf() function

Vulnerability Note VU#600777

Original Release Date: 2002-10-17 | Last Revised: 2002-10-17

Overview

A remotely exploitable buffer overflow vulnerability exists in gv.

Description

A remotely exploitable buffer overflow vulnerability exists in gv. gv allows a user to view and navigate PostScript and PDF documents by providing an interface to the ghostscript interpreter. This vulnerability can allow a remote attacker to execute arbitrary code on a vulnerable host.

Impact

A remote attacker can execute arbitrary code on a vulnerable host with the privileges of the victim.

Solution

Apply a patch.

Vendor Information

600777
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to David Endler for reporting this vulnerability.

This document was written by Ian A Finlay.

Other Information

CVE IDs: CVE-2002-0838
Severity Metric: 16.50
Date Public: 2002-09-26
Date First Published: 2002-10-17
Date Last Updated: 2002-10-17 20:02 UTC
Document Revision: 14

Sponsored by CISA.