PT-2010-5639 · Debian · Ghostscript

Vincent Danen

·

Published

1970-01-01

·

Updated

2017-08-17

·

CVE-2009-4897

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ghostscript versions 8.64 and earlier
Description The issue concerns multiple vulnerabilities in the Ghostscript package of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A buffer overflow in the gs/psi/iscan.c file of Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a crafted PDF document containing a long name.
Recommendations For Ghostscript versions 8.64 and earlier, update to a version later than 8.64 to resolve the issue. As a temporary workaround, consider restricting the use of Ghostscript to minimize the risk of exploitation until a patch is available. Avoid using Ghostscript to process untrusted or crafted PDF documents until the issue is resolved. At the moment, there is no information about other specific mitigation measures for this vulnerability.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01920
BDU:2015-01921
BDU:2015-01922
BDU:2015-01923
BDU:2015-01924
BDU:2015-01925
BDU:2015-01926
CVE-2009-4897
DSA-2093-1

Affected Products

Ghostscript