CVE-2006-5864 evince contains a buffer overflow in get_next_text()
Published Nov 11, 2006
5.1
MEDIUMCVSS 2.0
EPSS 15.21%
Description
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.
Affected products
Remediation
Red Hat statement
Red Hat is aware of this issue and is tracking it via the following bug for Red Hat Enterprise Linux 2.1. This issue did not affect Red Hat Enterprise Linux 3 or 4. https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=215593 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/ Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 2.1 which is in maintenance mode.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 15.21% (0.15211) | 96.66th | v5 (v2026.06.15) |
| Jun 15, 2026 | 14.84% (0.14838) | 96.26th | v5 (v2026.06.15) |
| Mar 24, 2026 | 30.73% (0.30732) | 96.67th | v4 (v2025.03.14) |
| Feb 6, 2026 | 32.79% (0.32786) | 96.75th | v4 (v2025.03.14) |
| Aug 22, 2025 | 28.00% (0.27997) | 96.28th | v4 (v2025.03.14) |
| Mar 30, 2025 | 30.64% (0.30643) | 96.32th | v4 (v2025.03.14) |
| Mar 29, 2025 | 36.45% (0.36452) | 95.58th | v4 (v2025.03.14) |
| Mar 19, 2025 | 30.64% (0.30643) | 96.14th | v4 (v2025.03.14) |
| Mar 17, 2025 | 36.65% (0.36649) | 96.77th | v4 (v2025.03.14) |
| Dec 17, 2024 | 94.08% (0.94079) | 99.37th | v3 (v2023.03.01) |
| Sep 14, 2023 | 92.34% (0.92342) | 98.61th | v3 (v2023.03.01) |
| Aug 7, 2023 | 92.89% (0.92891) | 98.64th | v3 (v2023.03.01) |
| Jun 30, 2023 | 92.83% (0.92833) | 98.59th | v3 (v2023.03.01) |
| Mar 7, 2023 | 92.91% (0.92905) | 98.43th | v3 (v2023.03.01) |
| Mar 6, 2023 | 27.99% (0.27992) | 97.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 27.99% (0.27992) | 95.99th | v2 (v2022.01.01) |
References (43)
- http://secunia.com/advisories/22787 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22932 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23006 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23018 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23111 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23118 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23183 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23266 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23306 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23335 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23353 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23409 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23579 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24649 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24787 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-200611-20.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200703-24.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200704-06.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2006/dsa-1214 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-1243 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/352825 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:214 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:229 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_26_sr.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_28_sr.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_29_sr.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/archive/1/451057/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/451422/100/200/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/452868/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/20978 vdb-entryx_refsource_BIDExploit
- http://www.ubuntu.com/usn/usn-390-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-390-2 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-390-3 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/4424 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/4747 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-5864 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=217672 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30153 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30555 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-850 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-5864
- https://www.cve.org/CVERecord?id=CVE-2006-5864
- https://www.exploit-db.com/exploits/2858 exploitx_refsource_EXPLOIT-DB
Change history (0)
No recorded changes yet.