Debians sikkerhedsbulletin

DSA-182-1 kdegraphics -- bufferoverløb

Rapporteret den:
28. okt 2002
Berørte pakker:
kdegraphics
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 5808.
I Mitres CVE-ordbog: CVE-2002-0838.
Yderligere oplysninger:

Zen-parse har opdaget et bufferoverløb i gv, en PostScript- og PDF-fremviser til X11. Den samme kode findes i kghostview som er en del af pakken KDE-Graphics. Problemet opstår når PostScript-filen scannes og kan udnyttes af en angriber der sender en misdannet PostScript- eller PDF-fil. Angriberen kan få afviklet vilkårlig kode med offerets rettigheder.

Dette problem er rettet i version 2.2.2-6.8 i den aktuelle stabile distribution (woody) og i version 2.2.2-6.9 i den ustabile distribution (sid). Den gamle stabile distribution (potato) er ikke påvirket, da KDE ikke er indeholdt i den.

Vi anbefaler at du opgraderer din kghostview-pakke.

Rettet i:

Debian GNU/Linux 3.0 (woody)

Kildekode:
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2-6.8.dsc
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2-6.8.diff.gz
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_ia64.deb
HP Precision:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_sparc.deb

MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.