Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade evinceUpgrade gv | Jul 30, 2024 | Nov 11, 2006 |
| Freebsd | — | Upgrade evince | Dec 10, 2025 | Dec 14, 2006 |
| Gentoo Linux | — | Upgrade app-text/evince.Upgrade app-text/gv.Upgrade app-text/mgv. | Oct 30, 2017 | Nov 10, 2006 |
| Suse | — | Upgrade evinceUpgrade evince-docUpgrade evince-develUpgrade evince-lang | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade evinceUpgrade evince-gtk | Nov 8, 2024 | Nov 11, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub