| Description: | The remote host is missing an update to evince announced via advisory USN-390-2.
A security issue affects the following Ubuntu releases:
Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
USN-390-1 fixed a vulnerability in evince. The original fix did not fully solve the problem, allowing for a denial of service in certain situations.
Original advisory details:
A buffer overflow was discovered in the PostScript processor included in evince. By tricking a user into opening a specially crafted PS file, an attacker could crash evince or execute arbitrary code with the user's privileges.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 5.10: evince 0.4.0-0ubuntu4.3
Ubuntu 6.06 LTS: evince 0.5.2-0ubuntu3.2
Ubuntu 6.10: evince 0.6.1-0ubuntu1.2
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-390-2
Risk factor : High |