CVE-2009-4897
published 2010-07-22CVE-2009-4897: Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.63%
93.1th percentile
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | afpl_ghostscript | — | — |
| artifex | ghostscript | >= 0 < 8.70~dfsg-1 | 8.70~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.70~dfsg-1 | 8.70~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.70~dfsg-1 | 8.70~dfsg-1 |
| artifex | ghostscript | >= 0 < 8.70~dfsg-1 | 8.70~dfsg-1 |
| artifex | ghostscript_fonts | — | — |
| artifex | gpl_ghostscript | <= 8.64 | — |
| artifex | gpl_ghostscript | — | — |
| artifex | gpl_ghostscript | — | — |
| artifex | gpl_ghostscript | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2010-07-13·CVSS 9.3
CVE-2010-1628 [CRITICAL] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
David Srbecky discovered that Ghostscript incorrectly handled debug
logging. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. This issue only
affected Ubuntu 9.04 and Ubuntu 9.10. The default compiler options for
affected releases should reduce the vulnerability to a denial of service.
(CVE-2009-4270)
It was discovered that Ghostscript incorrectly handled certain malformed
files. If a user or automated system were tricked into opening a crafted
Postscript or PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
This issue only affecte
Red Hat
ghostscript: long name buffer overflow (GS 8.64)
vendor_redhat·2009-06-08·CVSS 9.3
CVE-2009-4897 [CRITICAL] ghostscript: long name buffer overflow (GS 8.64)
ghostscript: long name buffer overflow (GS 8.64)
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
Package: ghostscript (Red Hat Enterprise Linux 4) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2009-4897: ghostscript - Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote ...
vendor_debian·2009·CVSS 9.3
CVE-2009-4897 [CRITICAL] CVE-2009-4897: ghostscript - Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote ...
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
Scope: local
bookworm: resolved (fixed in 8.70~dfsg-1)
bullseye: resolved (fixed in 8.70~dfsg-1)
forky: resolved (fixed in 8.70~dfsg-1)
sid: resolved (fixed in 8.70~dfsg-1)
trixie: resolved (fixed in 8.70~dfsg-1)
GHSA
GHSA-53pw-2446-9fc8: Buffer overflow in gs/psi/iscan
ghsa_unreviewed·2022-05-02
CVE-2009-4897 [HIGH] CWE-119 GHSA-53pw-2446-9fc8: Buffer overflow in gs/psi/iscan
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
OSV
CVE-2009-4897: Buffer overflow in gs/psi/iscan
osv·2010-07-22·CVSS 9.3
CVE-2009-4897 [CRITICAL] CVE-2009-4897: Buffer overflow in gs/psi/iscan
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
No detection rules found.
No public exploits indexed.
http://bugs.ghostscript.com/show_bug.cgi?id=690523http://secunia.com/advisories/40580http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:134http://www.mandriva.com/security/advisories?name=MDVSA-2010:135http://www.osvdb.org/66277http://www.securityfocus.com/bid/41593http://www.ubuntu.com/usn/USN-961-1https://bugzilla.redhat.com/show_bug.cgi?id=613792https://exchange.xforce.ibmcloud.com/vulnerabilities/60380http://bugs.ghostscript.com/show_bug.cgi?id=690523http://secunia.com/advisories/40580http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:134http://www.mandriva.com/security/advisories?name=MDVSA-2010:135http://www.osvdb.org/66277http://www.securityfocus.com/bid/41593http://www.ubuntu.com/usn/USN-961-1https://bugzilla.redhat.com/show_bug.cgi?id=613792https://exchange.xforce.ibmcloud.com/vulnerabilities/60380
2010-07-22
Published