4.3
CVSSv2

CVE-2010-4054

Published: 23/10/2010 Updated: 09/01/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The gs_type2_interpret function in Ghostscript allows remote malicious users to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.

Vulnerable Product Search on Vulmon Subscribe to Product

artifex afpl ghostscript 7.00

artifex afpl ghostscript 6.50

artifex afpl ghostscript 6.01

artifex afpl ghostscript 6.0

artifex ghostscript fonts 8.11

artifex gpl ghostscript 8.01

artifex ghostscript fonts 6.0

artifex gpl ghostscript 8.62

artifex gpl ghostscript 8.63

artifex afpl ghostscript 8.50

artifex afpl ghostscript 8.14

artifex afpl ghostscript 8.13

artifex afpl ghostscript 8.12

artifex gpl ghostscript 8.51

artifex gpl ghostscript 8.54

artifex gpl ghostscript 8.71

artifex afpl ghostscript 8.53

artifex afpl ghostscript 7.03

artifex gpl ghostscript 8.70

artifex afpl ghostscript 8.52

artifex afpl ghostscript 8.00

artifex gpl ghostscript 8.50

artifex gpl ghostscript 8.61

artifex gpl ghostscript 8.57

artifex afpl ghostscript 8.54

artifex afpl ghostscript 7.04

artifex gpl ghostscript 8.64

artifex afpl ghostscript 8.51

artifex afpl ghostscript 8.11

artifex gpl ghostscript 8.15

artifex gpl ghostscript 8.60

artifex gpl ghostscript 8.56

artifex afpl ghostscript 9.0

Vendor Advisories

Ghostscript could be made to crash or run programs as your login if it opened a specially crafted file ...
Synopsis Moderate: ghostscript security update Type/Severity Security Advisory: Moderate Topic Updated ghostscript packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Comm ...
Synopsis Moderate: ghostscript security update Type/Severity Security Advisory: Moderate Topic Updated ghostscript packages that fix two security issues are now availablefor Red Hat Enterprise Linux 4The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerab ...
An integer overflow flaw was found in Ghostscript's TrueType bytecode interpreter An attacker could create a specially-crafted PostScript or PDF file that, when interpreted, could cause Ghostscript to crash or, potentially, execute arbitrary code (CVE-2009-3743) It was found that Ghostscript always tried to read Ghostscript system initialization ...