CVE-2009-3743
published 2010-08-26CVE-2009-3743: Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.75%
93.3th percentile
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | ghostscript | >= 0 < 8.71~dfsg-1 | 8.71~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-1 | 8.71~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-1 | 8.71~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-1 | 8.71~dfsg-1 |
| artifex | ghostscript_fonts | — | — |
| artifex | ghostscript_fonts | — | — |
| artifex | gpl_ghostscript | <= 8.70 | — |
| artifex | gpl_ghostscript | — | — |
| artifex | gpl_ghostscript | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2012-01-04·CVSS 9.3
CVE-2008-3520 [CRITICAL] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that Ghostscript did not correctly handle memory
allocation when parsing certain malformed JPEG-2000 images. If a user or
automated system were tricked into opening a specially crafted image, an
attacker could cause a denial of service and possibly execute arbitrary
code with user privileges. (CVE-2008-3520)
It was discovered that Ghostscript did not correctly handle certain
formatting operations when parsing JPEG-2000 images. If a user or automated
system were tricked into opening a specially crafted image, an attacker
could cause a denial of service and possibly execute arbitrary code with
user privileges. (CVE-2008-3522)
Red Hat
ghostscript: TrueType bytecode intepreter integer overflow or wraparound
vendor_redhat·2010-08-24·CVSS 9.3
CVE-2009-3743 [CRITICAL] CWE-190 ghostscript: TrueType bytecode intepreter integer overflow or wraparound
ghostscript: TrueType bytecode intepreter integer overflow or wraparound
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Package: ghostscript (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2009-3743: ghostscript - Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter...
vendor_debian·2009·CVSS 9.3
CVE-2009-3743 [CRITICAL] CVE-2009-3743: ghostscript - Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter...
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 8.71~dfsg-1)
bullseye: resolved (fixed in 8.71~dfsg-1)
forky: resolved (fixed in 8.71~dfsg-1)
sid: resolved (fixed in 8.71~dfsg-1)
trixie: resolved (fixed in 8.71~dfsg-1)
GHSA
GHSA-3p47-jqhp-gxp9: Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8
ghsa_unreviewed·2022-05-02
CVE-2009-3743 [HIGH] GHSA-3p47-jqhp-gxp9: Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
OSV
CVE-2009-3743: Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8
osv·2010-08-26·CVSS 9.3
CVE-2009-3743 [CRITICAL] CVE-2009-3743: Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2055 CVE-2009-3743 ghostscript various flaws [fedora-all]
bugzilla·2011-11-22·CVSS 9.3
CVE-2010-2055 [CRITICAL] CVE-2010-2055 CVE-2009-3743 ghostscript various flaws [fedora-all]
CVE-2010-2055 CVE-2009-3743 ghostscript various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=599
Bugzilla
CVE-2009-3743 ghostscript: TrueType bytecode intepreter integer overflow or wraparound
bugzilla·2010-08-27·CVSS 9.3
CVE-2009-3743 [CRITICAL] CVE-2009-3743 ghostscript: TrueType bytecode intepreter integer overflow or wraparound
CVE-2009-3743 ghostscript: TrueType bytecode intepreter integer overflow or wraparound
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3743 to
the following vulnerability:
Off-by-one error in the TrueType bytecode interpreter in Ghostscript
before 8.71 allows remote attackers to execute arbitrary code or cause
a denial of service (heap memory corruption) via a malformed TrueType
font in a document.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3743
[2] http://www.kb.cert.org/vuls/id/JALR-87YGN8
[3] http://www.kb.cert.org/vuls/id/644319
Upstream bug report:
[4] http://bugs.ghostscript.com/show_bug.cgi?id=691044
Upstream changeset:
[5] http://code.google.com/p/ghostscript/source/detail?r=10602
Discussion:
(In reply to comment #0)
> Off-by-
http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.kb.cert.org/vuls/id/644319http://www.kb.cert.org/vuls/id/JALR-87YGN8http://www.securityfocus.com/archive/1/514892/100/0/threadedhttp://www.securitytracker.com/id?1024785https://rhn.redhat.com/errata/RHSA-2012-0095.htmlhttp://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.kb.cert.org/vuls/id/644319http://www.kb.cert.org/vuls/id/JALR-87YGN8http://www.securityfocus.com/archive/1/514892/100/0/threadedhttp://www.securitytracker.com/id?1024785https://rhn.redhat.com/errata/RHSA-2012-0095.html
2010-08-26
Published