CVE-2009-4897Improper Restriction of Operations within the Bounds of a Memory Buffer in GPL Ghostscript

Severity
9.3CRITICALNVD
EPSS
8.3%
top 7.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateMay 2

Description

Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

Debianartifex/ghostscript< 8.70~dfsg-1+3
NVDartifex/afpl_ghostscript16 versions+15

Patches

🔴Vulnerability Details

3
GHSA
GHSA-53pw-2446-9fc8: Buffer overflow in gs/psi/iscan2022-05-02
CVEList
CVE-2009-4897: Buffer overflow in gs/psi/iscan2010-07-22
OSV
CVE-2009-4897: Buffer overflow in gs/psi/iscan2010-07-22

📋Vendor Advisories

3
Ubuntu
Ghostscript vulnerabilities2010-07-13
Red Hat
ghostscript: long name buffer overflow (GS 8.64)2009-06-08
Debian
CVE-2009-4897: ghostscript - Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote ...2009

💬Community

1
Bugzilla
CVE-2009-4897 ghostscript: long name buffer overflow (GS 8.64)2010-07-12
CVE-2009-4897 — Artifex GPL Ghostscript vulnerability | cvebase