Рекомендация Debian по безопасности

DSA-182-1 kdegraphics -- переполнение буфера

Дата сообщения:
28.10.2002
Затронутые пакеты:
kdegraphics
Уязвим:
Да
Ссылки на базы данных по безопасности:
В базе данных Bugtraq (на SecurityFocus): Идентификатор BugTraq 5808.
В каталоге Mitre CVE: CVE-2002-0838.
Более подробная информация:

Zen-parse обнаружил переполнение буфера в gv, программе для просмотра PostScript и PDF для X11. Тот же код присутствует в kghostview, который является частью пакета KDE-Graphics. Эта проблема возникает при сканировании файла в формате PostScript и может использоваться злоумышленником путём отправки специально сформированного файла PostScript или PDF. Злоумышленник способен выполнить произвольный код с правами жертвы.

Эта проблема была исправлена в версии 2.2.2-6.8 для текущего стабильного выпуска (woody) и в версии 2.2.2-6.9 для нестабильного выпуска (sid). Предыдущий стабильный выпуск (potato) не подвержен данной проблеме, поскольку в нём отсутствует KDE.

Рекомендуется обновить пакет kghostview.

Исправлено в:

Debian GNU/Linux 3.0 (woody)

Исходный код:
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2-6.8.dsc
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2-6.8.diff.gz
http://security.debian.org/pool/updates/main/k/kdegraphics/kdegraphics_2.2.2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_alpha.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_arm.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_i386.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_ia64.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_ia64.deb
HP Precision:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_hppa.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_m68k.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_mips.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_s390.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/kdegraphics/kamera_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kcoloredit_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kfract_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kghostview_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kiconedit_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kooka_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kpaint_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kruler_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/ksnapshot_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/kview_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan-dev_2.2.2-6.8_sparc.deb
http://security.debian.org/pool/updates/main/k/kdegraphics/libkscan1_2.2.2-6.8_sparc.deb

Контрольные суммы MD5 этих файлов доступны в исходном сообщении.