|
|
| |
|
| |
ghostscript: code execution
| Package(s): | ghostscript |
CVE #(s): | CVE-2012-4405
|
| Created: | September 12, 2012 |
Updated: | April 10, 2013 |
| Description: |
From the Red Hat advisory:
An integer overflow flaw, leading to a heap-based buffer overflow, was
found in Ghostscript's International Color Consortium Format library
(icclib). An attacker could create a specially-crafted PostScript or PDF
file with embedded images that would cause Ghostscript to crash or,
potentially, execute arbitrary code with the privileges of the user running
Ghostscript. |
| Alerts: |
|
( Log in to post comments)
|
|
|