LWN.net Logo

ghostscript: multiple vulnerabilities

Package(s):ghostscript CVE #(s):CVE-2009-4270 CVE-2009-4897 CVE-2010-1628
Created:July 14, 2010 Updated:August 19, 2010
Description: From the Ubuntu advisory:

David Srbecky discovered that Ghostscript incorrectly handled debug logging. If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program. (CVE-2009-4270)

It was discovered that Ghostscript incorrectly handled certain malformed files. If a user or automated system were tricked into opening a crafted Postscript or PDF file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program. (CVE-2009-4897)

Dan Rosenberg discovered that Ghostscript incorrectly handled certain recursive Postscript files. If a user or automated system were tricked into opening a crafted Postscript file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program. (CVE-2010-1628)

Alerts:
Debian DSA-2093-1 2010-08-19
SUSE SUSE-SR:2010:015 2010-08-17
Fedora FEDORA-2010-11376 2010-07-23
Fedora FEDORA-2010-11325 2010-07-23
SUSE SUSE-SR:2010:014 2010-08-02
Pardus 2010-101 2010-08-02
openSUSE openSUSE-SU-2010:0425-2 2010-08-02
Debian DSA-2080-1 2010-08-01
openSUSE openSUSE-SU-2010:0425-1 2010-07-23
Mandriva MDVSA-2010:136 2010-07-15
Mandriva MDVSA-2010:135 2010-07-15
Mandriva MDVSA-2010:134 2010-07-15
Ubuntu USN-961-1 2010-07-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds