First published: Mon Aug 16 2004(Updated: )
Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GeoVision | =3.4.2 | |
GeoVision | =3.5.2 | |
GeoVision | =3.1.4 | |
GeoVision | =3.4.12 | |
GeoVision | =2.7b4 | |
GeoVision | =3.5.3 | |
GeoVision | =3.2.4 | |
GeoVision | =2.9.4 | |
GeoVision | =2.7b1 | |
GeoVision | =2.7b5 | |
GeoVision | =3.1.6 | |
GeoVision | =2.7.6 | |
GeoVision | =3.0.0 | |
GeoVision | =3.0.4 | |
GeoVision | =3.4.3 | |
GeoVision | =2.7b3 | |
GeoVision | =3.5.8 | |
GeoVision | =2.7b2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1717 has a high severity rating due to multiple buffer overflows allowing remote code execution.
To fix CVE-2004-1717, you should update to a patched version of gv that addresses these buffer overflow vulnerabilities.
CVE-2004-1717 affects multiple versions of gv including 2.7b1, 2.7b2, 2.7b3, 2.7b4, 2.7b5, 2.7.6, 3.0.0, 3.0.4, 3.1.4, 3.1.6, 3.2.4, 3.4.2, 3.4.3, 3.4.12, 3.5.2, 3.5.3, and 3.5.8.
CVE-2004-1717 enables remote attackers to execute arbitrary code on vulnerable systems through crafted Postscript files.
A temporary workaround for CVE-2004-1717 is to avoid opening untrusted Postscript files until the software is updated.