PT-2008-2043 · Artifex+1 · Ghostscript+1

Chris Evans

·

Published

2008-02-27

·

Updated

2024-02-16

·

CVE-2008-0411

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ghostscript versions 8.61 and earlier
Description The issue allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator. This is due to a stack-based buffer overflow in the zseticcspace function in zicc.c.
Recommendations For Ghostscript versions 8.61 and earlier, update to a version later than 8.61 to resolve the issue. As a temporary workaround, consider restricting the use of postscript files or disabling the zseticcspace function until a patch is available. Avoid using the .seticcspace operator with long Range arrays in postscript files until the issue is resolved.

Exploit

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2008-0411
DSA-1510-1
RHSA-2008:0155
RHSA-2008_0155

Affected Products

Ghostscript
Red Hat