Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-5864

Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.314
EPSS Ranking 96.6%
CVSS Severity
CVSS v2 Score 5.1
References
Products affected by CVE-2006-5864
  • Gnu » Gv » Version: 3.5.8
    cpe:2.3:a:gnu:gv:3.5.8
  • Gnu » Gv » Version: 3.6.0
    cpe:2.3:a:gnu:gv:3.6.0
  • Gnu » Gv » Version: 3.6.1
    cpe:2.3:a:gnu:gv:3.6.1
  • Gnu » Gv » Version: 3.6.2
    cpe:2.3:a:gnu:gv:3.6.2


Contact Us

Shodan ® - All rights reserved