9.3
CVSSv2

CVE-2009-4897

Published: 22/07/2010 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and previous versions allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.

Vulnerable Product Search on Vulmon Subscribe to Product

artifex gpl ghostscript 8.63

artifex gpl ghostscript 8.62

artifex gpl ghostscript 8.61

artifex afpl ghostscript 8.13

artifex afpl ghostscript 8.12

artifex gpl ghostscript 8.56

artifex gpl ghostscript 8.57

artifex afpl ghostscript 7.00

artifex afpl ghostscript 6.0

artifex afpl ghostscript 8.52

artifex afpl ghostscript 8.51

artifex gpl ghostscript 8.15

artifex gpl ghostscript 8.50

artifex gpl ghostscript 8.71

artifex afpl ghostscript 8.53

artifex gpl ghostscript

artifex afpl ghostscript 8.50

artifex afpl ghostscript 8.14

artifex ghostscript fonts 8.11

artifex gpl ghostscript 8.01

artifex afpl ghostscript 8.54

artifex afpl ghostscript 7.04

artifex afpl ghostscript 7.03

artifex gpl ghostscript 8.60

artifex gpl ghostscript 8.70

artifex afpl ghostscript 8.11

artifex afpl ghostscript 8.00

artifex gpl ghostscript 8.51

artifex gpl ghostscript 8.54

artifex afpl ghostscript 6.01

artifex afpl ghostscript 6.50

Vendor Advisories

Debian Bug report logs - #584516 CVE-2010-1628: allows context-dependent attackers to execute arbitrary code Package: ghostscript; Maintainer for ghostscript is Debian Printing Team <debian-printing@listsdebianorg>; Source for ghostscript is src:ghostscript (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@ ...
David Srbecky discovered that Ghostscript incorrectly handled debug logging If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program This issue only affected Ubuntu 904 and Ubuntu 910 The default compiler op ...