USN-390-2: evince vulnerability

Publication date

6 December 2006

Overview

evince vulnerability


Details

USN-390-1 fixed a vulnerability in evince. The original fix did not
fully solve the problem, allowing for a denial of service in certain
situations.

Original advisory details:

A buffer overflow was discovered in the PostScript processor included
in evince. By tricking a user into opening a specially crafted PS
file, an attacker could crash evince or execute arbitrary code with
the user’s privileges.

USN-390-1 fixed a vulnerability in evince. The original fix did not
fully solve the problem, allowing for a denial of service in certain
situations.

Original advisory details:

A buffer overflow was discovered in the PostScript processor included
in evince. By tricking a user into opening a specially crafted PS
file, an attacker could crash evince or execute arbitrary code with
the user’s privileges.

Update instructions

In general, a standard system upgrade is sufficient to effect the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
6.10 edgy evince –  0.6.1-0ubuntu1.2
6.06 dapper evince –  0.5.2-0ubuntu3.2
5.10 breezy evince –  0.4.0-0ubuntu4.3

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›