Säkerhetsbulletin från Debian

DSA-182-1 kdegraphics -- buffertspill

Rapporterat den:
2002-10-28
Berörda paket:
kdegraphics
Sårbara:
Ja
Referenser i säkerhetsdatabaser:
I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 5808.
I Mitres CVE-förteckning: CVE-2002-0838.
Ytterligare information:

Zen-parse upptäckte ett buffertspill i gv, en PostScript- och PDF-visare för X11. Samma kod förekommer i kghostview som är en del av paketet KDE-Graphics. Problemet uppstår då PostScriptfilen genomsöks och kan utnyttjas av en angripare genom att sända en felaktig PostScript- eller PDF-fil. Angriparen kan få godtycklig kod att köras med offrets privilegier.

Detta problem har rättats i version 2.2.2-6.8 för den nuvarande stabila utgåvan (Woody) samt i version 2.2.2-6.9 för den instabila utgåvan (Sid). Den gamla stabila utgåvan (Potato) berörs inte eftersom den inte innehåller KDE.

Vi rekommenderar att ni uppgraderar ert kghostview-paket.

Rättat i:

Debian GNU/Linux 3.0 (woody)

Källkod:
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2-6.8.dsc
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2-6.8.diff.gz
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_ia64.deb
HP Precision:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_sparc.deb

MD5-kontrollsummor för dessa filer finns i originalbulletinen.