PT-2009-1048 · Artifex+2 · Ghostscript+2

Publicado

2009-04-08

·

Atualizado

2018-10-15

·

CVE-2007-6725

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ghostscript versions 8.60 through 8.61 hpijs-1.3
Description The issue allows remote attackers to cause problems, including a denial of service, and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf decode 2d function. Multiple vulnerabilities in the hpijs package may lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For Ghostscript versions 8.60 through 8.61, update to a version that fixes the buffer underflow issue in the cf decode 2d function. For hpijs-1.3, apply the necessary security patches to address the multiple vulnerabilities. At the moment, there is no information about a newer version that contains a fix for this vulnerability in hpijs.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06205
CVE-2007-6725
DSA-2080-1
RHSA-2009:0420
RHSA-2009:0421
RHSA-2009_0420
RHSA-2009_0421

Produtos afetados

Ghostscript
Red Hat
Hpijs