CVE-2009-0196
published 2009-04-16CVE-2009-0196: Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.36%
93.7th percentile
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| debian | ghostscript | < ghostscript 8.64~dfsg-1.1 (bookworm) | ghostscript 8.64~dfsg-1.1 (bookworm) |
| debian | jbig2dec | < ghostscript 8.64~dfsg-1.1 (bookworm) | ghostscript 8.64~dfsg-1.1 (bookworm) |
| ghostscript | ghostscript | <= 8.64 | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2009-04-15·CVSS 7.5
CVE-2007-6725 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript vulnerabilities
It was discovered that Ghostscript contained a buffer underflow in its
CCITTFax decoding filter. If a user or automated system were tricked into
opening a crafted PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
(CVE-2007-6725)
It was discovered that Ghostscript contained a buffer overflow in the
BaseFont writer module. If a user or automated system were tricked into
opening a crafted Postscript file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program. (CVE-2008-6679)
It was discovered that Ghostscript contained additional integer overflows
in its ICC color management
Red Hat
ghostscript: Missing boundary check in Ghostscript's jbig2dec library
vendor_redhat·2009-04-08·CVSS 9.3
CVE-2009-0196 [CRITICAL] ghostscript: Missing boundary check in Ghostscript's jbig2dec library
ghostscript: Missing boundary check in Ghostscript's jbig2dec library
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
Debian
CVE-2009-0196: ghostscript - Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol...
vendor_debian·2009·CVSS 9.3
CVE-2009-0196 [CRITICAL] CVE-2009-0196: ghostscript - Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol...
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
Scope: local
bookworm: resolved (fixed in 8.64~dfsg-1.1)
bullseye: resolved (fixed in 8.64~dfsg-1.1)
forky: resolved (fixed in 8.64~dfsg-1.1)
sid: resolved (fixed in 8.64~dfsg-1.1)
trixie: resolved (fixed in 8.64~dfsg-1.1)
GHSA
GHSA-76p8-fv4q-j2wv: Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict
ghsa_unreviewed·2022-05-02
CVE-2009-0196 [HIGH] CWE-119 GHSA-76p8-fv4q-j2wv: Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
OSV
CVE-2009-0196: Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict
osv·2009-04-16·CVSS 9.3
CVE-2009-0196 [CRITICAL] CVE-2009-0196: Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
bugzilla·2009-04-15·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
*** Bug 480775 has been marked as a duplicate of this bug. ***
---
ghostscript-8.63-6.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/ghostscript-8.63-6.fc10
---
ghostscript-8.63-6.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
bugzilla·2009-04-15·CVSS 9.3
CVE-2009-0196 [CRITICAL] CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora 11 development cycle.
Changing version to '11'.
More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping
Bugzilla
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
bugzilla·2009-04-15·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
ghostscript-8.63-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/ghostscript-8.63-3.fc9
---
ghostscript-8.63-3.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-0196 ghostscript: Missing boundary check in Ghostscript's jbig2dec library
bugzilla·2009-04-01·CVSS 9.3
CVE-2009-0196 [CRITICAL] CVE-2009-0196 ghostscript: Missing boundary check in Ghostscript's jbig2dec library
CVE-2009-0196 ghostscript: Missing boundary check in Ghostscript's jbig2dec library
A missing boundary check flaw was found in the Ghostscript's JBIG2 decoding library. An attacker could create a specially-crafted PDF file which could
cause Ghostscript to crash, or, potentially execute arbitrary code, when
opened by the victim.
Acknowledgements:
Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly reporting this flaw.
Discussion:
This issue was reported by Alin Rad Pop, Secunia Research.
---
Created attachment 337747
Upstream patch from Ralph Giles
---
Secunia advisory:
http://secunia.com/secunia_research/2009-21/
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2009:0421 https://rhn.redhat.com/errata/RHSA-200
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://osvdb.org/53492http://secunia.com/advisories/34292http://secunia.com/advisories/34667http://secunia.com/advisories/34729http://secunia.com/advisories/34732http://secunia.com/advisories/35416http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://secunia.com/secunia_research/2009-21/http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://wiki.rpath.com/Advisories:rPSA-2009-0060http://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.redhat.com/support/errata/RHSA-2009-0421.htmlhttp://www.securityfocus.com/archive/1/502586/100/0/threadedhttp://www.securityfocus.com/archive/1/502757/100/0/threadedhttp://www.securityfocus.com/bid/34445http://www.securitytracker.com/id?1022029http://www.vupen.com/english/advisories/2009/0983http://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/attachment.cgi?id=337747https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10533https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://osvdb.org/53492http://secunia.com/advisories/34292http://secunia.com/advisories/34667http://secunia.com/advisories/34729http://secunia.com/advisories/34732http://secunia.com/advisories/35416http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://secunia.com/secunia_research/2009-21/http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://wiki.rpath.com/Advisories:rPSA-2009-0060http://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.redhat.com/support/errata/RHSA-2009-0421.htmlhttp://www.securityfocus.com/archive/1/502586/100/0/threadedhttp://www.securityfocus.com/archive/1/502757/100/0/threadedhttp://www.securityfocus.com/bid/34445http://www.securitytracker.com/id?1022029http://www.vupen.com/english/advisories/2009/0983http://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/attachment.cgi?id=337747https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10533https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.html
2009-04-16
Published