cbcvebase.
CVE-2009-0196
published 2009-04-16

CVE-2009-0196: Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and…

PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.36%
93.7th percentile
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.

Affected

20 ranges
VendorProductVersion rangeFixed in
artifexghostscript>= 0 < 8.64~dfsg-1.18.64~dfsg-1.1
artifexghostscript>= 0 < 8.64~dfsg-1.18.64~dfsg-1.1
artifexghostscript>= 0 < 8.64~dfsg-1.18.64~dfsg-1.1
artifexghostscript>= 0 < 8.64~dfsg-1.18.64~dfsg-1.1
debianghostscript< ghostscript 8.64~dfsg-1.1 (bookworm)ghostscript 8.64~dfsg-1.1 (bookworm)
debianjbig2dec< ghostscript 8.64~dfsg-1.1 (bookworm)ghostscript 8.64~dfsg-1.1 (bookworm)
ghostscriptghostscript<= 8.64
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript
ghostscriptghostscript

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.