CVE-2008-6679
published 2009-04-08CVE-2008-6679: Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.50%
90.5th percentile
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 8.64~dfsg-1 | 8.64~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1 | 8.64~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1 | 8.64~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1 | 8.64~dfsg-1 |
| debian | ghostscript | < ghostscript 8.64~dfsg-1 (bookworm) | ghostscript 8.64~dfsg-1 (bookworm) |
| ghostscript | ghostscript | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6p24-mjw7-mgwh: Buffer overflow in the BaseFont writer module in Ghostscript 8
ghsa_unreviewed·2022-05-14
CVE-2008-6679 [MEDIUM] CWE-119 GHSA-6p24-mjw7-mgwh: Buffer overflow in the BaseFont writer module in Ghostscript 8
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
OSV
CVE-2008-6679: Buffer overflow in the BaseFont writer module in Ghostscript 8
osv·2009-04-08·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679: Buffer overflow in the BaseFont writer module in Ghostscript 8
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2009-04-15·CVSS 7.5
CVE-2007-6725 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript vulnerabilities
It was discovered that Ghostscript contained a buffer underflow in its
CCITTFax decoding filter. If a user or automated system were tricked into
opening a crafted PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
(CVE-2007-6725)
It was discovered that Ghostscript contained a buffer overflow in the
BaseFont writer module. If a user or automated system were tricked into
opening a crafted Postscript file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program. (CVE-2008-6679)
It was discovered that Ghostscript contained additional integer overflows
in its ICC color management
Red Hat
ghostscript: Buffer overflow in BaseFont writer module for pdfwrite device
vendor_redhat·2008-12-22·CVSS 5.0
CVE-2008-6679 [MEDIUM] ghostscript: Buffer overflow in BaseFont writer module for pdfwrite device
ghostscript: Buffer overflow in BaseFont writer module for pdfwrite device
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
Debian
CVE-2008-6679: ghostscript - Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly ...
vendor_debian·2008·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679: ghostscript - Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly ...
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
Scope: local
bookworm: resolved (fixed in 8.64~dfsg-1)
bullseye: resolved (fixed in 8.64~dfsg-1)
forky: resolved (fixed in 8.64~dfsg-1)
sid: resolved (fixed in 8.64~dfsg-1)
trixie: resolved (fixed in 8.64~dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
bugzilla·2009-04-15·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
*** Bug 480775 has been marked as a duplicate of this bug. ***
---
ghostscript-8.63-6.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/ghostscript-8.63-6.fc10
---
ghostscript-8.63-6.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
bugzilla·2009-04-15·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
ghostscript-8.63-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/ghostscript-8.63-3.fc9
---
ghostscript-8.63-3.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2008-6679 ghostscript: Buffer overflow in BaseFont writer module for pdfwrite device
bugzilla·2009-04-01·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679 ghostscript: Buffer overflow in BaseFont writer module for pdfwrite device
CVE-2008-6679 ghostscript: Buffer overflow in BaseFont writer module for pdfwrite device
Created attachment 337627
PoC proving presence of the flaw
Discussion:
A buffer overflow flaw was found in Ghostscript's BaseFont writer module
for pdfwrite device. An attacker could create a specially-crafted Postscript file
which could cause ps2pdf to crash, or, potentially execute arbitrary
code, when ps2pdf was used to convert it to equivalent PDF file.
References:
http://bugs.ghostscript.com/show_bug.cgi?id=690211
http://svn.ghostscript.com/viewvc?view=rev&sortby=rev&revision=9304
---
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-6679 to
the following vulnerability:
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and
possibly other versions, allows
http://bugs.ghostscript.com/show_bug.cgi?id=690211http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://secunia.com/advisories/34667http://secunia.com/advisories/34729http://secunia.com/advisories/34732http://secunia.com/advisories/35416http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://wiki.rpath.com/Advisories:rPSA-2009-0060http://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.openwall.com/lists/oss-security/2009/04/01/10http://www.redhat.com/support/errata/RHSA-2009-0421.htmlhttp://www.securityfocus.com/archive/1/502757/100/0/threadedhttp://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/show_bug.cgi?id=493445https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10019https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.htmlhttp://bugs.ghostscript.com/show_bug.cgi?id=690211http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://secunia.com/advisories/34667http://secunia.com/advisories/34729http://secunia.com/advisories/34732http://secunia.com/advisories/35416http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://wiki.rpath.com/Advisories:rPSA-2009-0060http://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.openwall.com/lists/oss-security/2009/04/01/10http://www.redhat.com/support/errata/RHSA-2009-0421.htmlhttp://www.securityfocus.com/archive/1/502757/100/0/threadedhttp://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/show_bug.cgi?id=493445https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10019https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.html
2009-04-08
Published