LWN.net Logo

ghostscript: code execution

Package(s):ghostscript CVE #(s):CVE-2009-3743
Created:January 4, 2012 Updated:February 6, 2012
Description: From the CVE entry: Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Alerts:
Ubuntu USN-1317-1 2012-01-04
Red Hat RHSA-2012:0095-01 2012-02-02
CentOS CESA-2012:0095 2012-02-03
CentOS CESA-2012:0095 2012-02-03
Scientific Linux SL-ghos-20120203 2012-02-03
Oracle ELSA-2012-0095 2012-02-03
Oracle ELSA-2012-0095 2012-02-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds