CVE-2009-4270
published 2009-12-21CVE-2009-4270: Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.90%
93.4th percentile
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 8.70~dfsg-2.1 | 8.70~dfsg-2.1 |
| artifex | ghostscript | >= 0 < 8.70~dfsg-2.1 | 8.70~dfsg-2.1 |
| artifex | ghostscript | >= 0 < 8.70~dfsg-2.1 | 8.70~dfsg-2.1 |
| artifex | ghostscript | >= 0 < 8.70~dfsg-2.1 | 8.70~dfsg-2.1 |
| debian | ghostscript | < ghostscript 8.70~dfsg-2.1 (bookworm) | ghostscript 8.70~dfsg-2.1 (bookworm) |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2010-07-13·CVSS 9.3
CVE-2010-1628 [CRITICAL] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
David Srbecky discovered that Ghostscript incorrectly handled debug
logging. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. This issue only
affected Ubuntu 9.04 and Ubuntu 9.10. The default compiler options for
affected releases should reduce the vulnerability to a denial of service.
(CVE-2009-4270)
It was discovered that Ghostscript incorrectly handled certain malformed
files. If a user or automated system were tricked into opening a crafted
Postscript or PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
This issue only affecte
Debian
CVE-2009-4270: ghostscript - Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghosts...
vendor_debian·2009·CVSS 9.3
CVE-2009-4270 [CRITICAL] CVE-2009-4270: ghostscript - Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghosts...
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
Scope: local
bookworm: resolved (fixed in 8.70~dfsg-2.1)
bullseye: resolved (fixed in 8.70~dfsg-2.1)
forky: resolved (fixed in 8.70~dfsg-2.1)
sid: resolved (fixed in 8.70~dfsg-2.1)
trixie: resolved (fixed in 8.70~dfsg-2.1)
Red Hat
CVE-2009-4270 ghostscript buffer overflow in cups output driver
vendor_redhat·CVSS 9.3
CVE-2009-4270 [CRITICAL] CVE-2009-4270 ghostscript buffer overflow in cups output driver
CVE-2009-4270 ghostscript buffer overflow in cups output driver
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
Statement: Not vulnerable. This issue did not affect the versions of ghostscript as shipped with Red Hat Enterprise Linux 3, 4, or 5.
GHSA
GHSA-m27g-4vw6-6c82: Stack-based buffer overflow in the errprintf function in base/gsmisc
ghsa_unreviewed·2022-05-02
CVE-2009-4270 [HIGH] CWE-119 GHSA-m27g-4vw6-6c82: Stack-based buffer overflow in the errprintf function in base/gsmisc
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
OSV
CVE-2009-4270: Stack-based buffer overflow in the errprintf function in base/gsmisc
osv·2009-12-21·CVSS 9.3
CVE-2009-4270 [CRITICAL] CVE-2009-4270: Stack-based buffer overflow in the errprintf function in base/gsmisc
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
No detection rules found.
No public exploits indexed.
http://bugs.ghostscript.com/show_bug.cgi?id=690829http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://osvdb.org/61140http://secunia.com/advisories/37851http://secunia.com/advisories/40580http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:134http://www.mandriva.com/security/advisories?name=MDVSA-2010:135http://www.openwall.com/lists/oss-security/2009/12/18/1http://www.openwall.com/lists/oss-security/2009/12/18/2http://www.securityfocus.com/bid/37410http://www.ubuntu.com/usn/USN-961-1http://www.vupen.com/english/advisories/2009/3597https://bugzilla.redhat.com/show_bug.cgi?id=540760http://bugs.ghostscript.com/show_bug.cgi?id=690829http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://osvdb.org/61140http://secunia.com/advisories/37851http://secunia.com/advisories/40580http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:134http://www.mandriva.com/security/advisories?name=MDVSA-2010:135http://www.openwall.com/lists/oss-security/2009/12/18/1http://www.openwall.com/lists/oss-security/2009/12/18/2http://www.securityfocus.com/bid/37410http://www.ubuntu.com/usn/USN-961-1http://www.vupen.com/english/advisories/2009/3597https://bugzilla.redhat.com/show_bug.cgi?id=540760
2009-12-21
Published