CVE-2006-5864

GNU gv 3.6.2 - Stack-based Buffer Overflow via Long Comments in PostScript Headers

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5864. PoCs published by K-sPecial.

AI-analyzed exploit summary This exploit generates a malicious PostScript file targeting a buffer overflow in Evince (CVE-2006-5864). It includes shellcode for a reverse shell and leverages a 'jmp *%esp' instruction to redirect execution.

Description

Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.

Exploits (1)

exploitdb WORKING POC VERIFIED
by K-sPecial · cremotelinux
https://www.exploit-db.com/exploits/2858

This exploit generates a malicious PostScript file targeting a buffer overflow in Evince (CVE-2006-5864). It includes shellcode for a reverse shell and leverages a 'jmp *%esp' instruction to redirect execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Evince (version not specified)
No auth needed
Prerequisites: Ability to deliver malicious PostScript file to target · Target must open the file with vulnerable Evince version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (39)

Core 39
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30153
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4424
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-390-2
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4747
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/352825
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/451057/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20978
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-850
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1214
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23018
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22932
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2858
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23353
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23306
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23266
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23579
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24787
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_26_sr.html
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_28_sr.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23409
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200704-06.xml
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200703-24.xml
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23335
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23111
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23183
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1243
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200611-20.xml
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/451422/100/200/threaded
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:214
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23006
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22787
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30555
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23118
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24649
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_29_sr.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/452868/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:229
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-390-3
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-390-1

Scores

EPSS 0.1484
EPSS Percentile 96.3%

Details

CWE
CWE-119
Status published
Products (4)
gnu/gv 3.5.8
gnu/gv 3.6.0
gnu/gv 3.6.1
gnu/gv 3.6.2
Published Nov 11, 2006
Tracked Since Feb 18, 2026