CVE-2010-1869
published 2010-05-12CVE-2010-1869: Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted…
PriorityP355critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
9.27%
94.8th percentile
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 8.71~dfsg-4 | 8.71~dfsg-4 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-4 | 8.71~dfsg-4 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-4 | 8.71~dfsg-4 |
| artifex | ghostscript | >= 0 < 8.71~dfsg-4 | 8.71~dfsg-4 |
| artifex | gpl_ghostscript | — | — |
| artifex | gpl_ghostscript | — | — |
| debian | ghostscript | < ghostscript 8.71~dfsg-4 (bookworm) | ghostscript 8.71~dfsg-4 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x54\x5a\xda\xd1\xd9\x72\xf4\x5a\x4a\x4a\x4a\x4a\x4a\x43\x43\x43\x43\x43\x43\x52\x59\x56\x54\x58\x33\x30\x56\x58\x34\x41\x50\x30\x41\x33\x48\x48\x30\x41\x30\x30\x41\x42\x41\x41\x42\x54\x41\x41\x51\x32\x41\x42\x32\x42\x42\x30\x42\x42\x58\x50\x38\x41\x43\x4a\x4a\x49\x50\x31\x49\x50\x46\x30\x45\x38\x4b\x4f\x44\x42\x42\x31\x51\x4c\x4d\x59\x4b\x57\x50\x50\x43\x5a\x45\x51\x42\x4a\x44\x42\x42\x4a\x44\x50\x4e\x50\x45\x31\x48\x4d\x4b\x30\x51\x47\x46\x30\x46\x30\x43\x5a\x45\x38\x51\x48\x48\x4d\x4b\x30\x4d\x59\x51\x57\x4a\x4c\x48\x30\x43\x5a\x48\x4d\x4d\x50\x4e\x50\x45\x4e\x48\x4d\x4d\x50\x50\x50\x50\x50\x43\x5a\x51\x4a\x50\x58\x48\x4d\x4d\x50\x4b\x4f\x50\x4f\x4a\x44\x43\x49\x4b\x46\x46\x30\x42\x48\x46\x4f\x46\x4f\x44\x33\x42\x48\x43\x58\x46\x4f\x43\x52\x45\x39\x42\x4e\x4b\x39\x4b\x53\x46\x30\x46\x34\x50\x53\x50\x50\x48\x30\x47\x4b\x48\x4d\x4d\x50\x41\x41
bytes↗
e!PS + 'A'x500 + shellcode addr \x40\xd9\xbf\xbf + \xef\xbe\xbf\xbf + \xff\xbf pattern
- →Malicious PostScript/PDF file triggers a stack-based buffer overflow in GhostScript's PS token parser. Look for crafted files with the magic bytes 'e!PS' at the start, followed by large padding buffers, delivered as .pdf or .ps files. ↗
- →The exploit drops a file named 'crash.pdf' and triggers execution via CUPS printing (cupsd). Monitor for gs/ghostscript processes spawned by cupsd opening unexpected PDF/PS files. ↗
- →Affected versions are GhostScript 8.64 and 8.70. Detect vulnerable installations by checking the ghostscript binary version; flag any gs process parsing untrusted PS/PDF input on these versions. ↗
- ·Red Hat Enterprise Linux 3, 4, and 5 are NOT affected by CVE-2010-1869; only RHEL 6 (ghostscript 8.70) was evaluated and found not affected as well. ↗
- ·Ubuntu impact is limited to specific releases: CVE-2010-1869 only affected Ubuntu 8.04 LTS, 9.04, and 9.10. ↗
- ·The exploit targets FreeBSD 8.0 specifically; hardcoded shellcode addresses (e.g., \x40\xd9\xbf\xbf) are platform-specific and will differ on other OS/architecture combinations. ↗
- ·Debian fixed this in ghostscript 8.71~dfsg-4 across all tracked branches (bookworm, bullseye, forky, sid, trixie). ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2010-07-13·CVSS 9.3
CVE-2010-1628 [CRITICAL] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
David Srbecky discovered that Ghostscript incorrectly handled debug
logging. If a user or automated system were tricked into opening a crafted
PDF file, an attacker could cause a denial of service or execute arbitrary
code with privileges of the user invoking the program. This issue only
affected Ubuntu 9.04 and Ubuntu 9.10. The default compiler options for
affected releases should reduce the vulnerability to a denial of service.
(CVE-2009-4270)
It was discovered that Ghostscript incorrectly handled certain malformed
files. If a user or automated system were tricked into opening a crafted
Postscript or PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
This issue only affecte
Red Hat
ghostscript: PS parser buffer overflow in token scanner
vendor_redhat·2010-05-11·CVSS 9.3
CVE-2010-1869 [CRITICAL] ghostscript: PS parser buffer overflow in token scanner
ghostscript: PS parser buffer overflow in token scanner
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
Statement: Not vulnerable. This issue did not affect the versions of ghostscript as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Package: ghostscript (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-1869: ghostscript - Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 ...
vendor_debian·2010·CVSS 9.3
CVE-2010-1869 [CRITICAL] CVE-2010-1869: ghostscript - Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 ...
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
Scope: local
bookworm: resolved (fixed in 8.71~dfsg-4)
bullseye: resolved (fixed in 8.71~dfsg-4)
forky: resolved (fixed in 8.71~dfsg-4)
sid: resolved (fixed in 8.71~dfsg-4)
trixie: resolved (fixed in 8.71~dfsg-4)
GHSA
GHSA-gpcm-hmx8-j7h9: Stack-based buffer overflow in the parser function in GhostScript 8
ghsa_unreviewed·2022-05-14
CVE-2010-1869 [HIGH] CWE-119 GHSA-gpcm-hmx8-j7h9: Stack-based buffer overflow in the parser function in GhostScript 8
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
OSV
CVE-2010-1869: Stack-based buffer overflow in the parser function in GhostScript 8
osv·2010-05-12·CVSS 9.3
CVE-2010-1869 [CRITICAL] CVE-2010-1869: Stack-based buffer overflow in the parser function in GhostScript 8
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
No detection rules found.
Bugzilla
CVE-2009-4897 ghostscript: long name buffer overflow (GS 8.64)
bugzilla·2010-07-12·CVSS 9.3
CVE-2009-4897 [CRITICAL] CVE-2009-4897 ghostscript: long name buffer overflow (GS 8.64)
CVE-2009-4897 ghostscript: long name buffer overflow (GS 8.64)
A memory corruption vulnerability caused by long names was discovered [1] in Ghostscript 8.64 and earlier. A specially crafted PDF file could result in the execution of arbitrary code if opened or printed (i.e. via CUPS).
This was corrected in upstream Ghostscript 8.70 [2], version 8.64 and previous are affected by this flaw (all the way back to Ghostscript 7.05).
References:
[1] http://bugs.ghostscript.com/show_bug.cgi?id=690523
[2] http://svn.ghostscript.com/viewvc?view=rev&revision=9797
Discussion:
This problem is similar to CVE-2010-1869 (bug #582300) as was noted in oss-security thread:
http://thread.gmane.org/gmane.comp.security.oss.general/3184
(In reply to comment #0)
> This was corrected in upstream Ghostscript
Bugzilla
CVE-2010-1628 ghostscript: internal stack overflow due to recursive calls
bugzilla·2010-05-14·CVSS 9.3
CVE-2010-1628 [CRITICAL] CVE-2010-1628 ghostscript: internal stack overflow due to recursive calls
CVE-2010-1628 ghostscript: internal stack overflow due to recursive calls
The following vulnerability was reported to Ubuntu's bug tracker [1] by Dan Rosenberg:
1. The Ghostscript interpreter fails to properly handle some cases of infinite recursion. By creating a .ps file with a sequence such as:
/A{pop 0 A 0} bind def
/product A 0
The interpreter's internal stack will be overflowed with recursive calls. Rather than gracefully handling this situation, the interpreter continues execution by jumping to an (usually invalid) address near (or past) the tail end of the stack. Without further manipulation, this would simply result in a segfault, but it turns out that by altering the number of variable definitions that occur before the call to the infinitely recursive procedure, the user can
Bugzilla
CVE-2010-1869 ghostscript: PS parser buffer overflow in token scanner
bugzilla·2010-04-14·CVSS 9.3
CVE-2010-1869 [CRITICAL] CVE-2010-1869 ghostscript: PS parser buffer overflow in token scanner
CVE-2010-1869 ghostscript: PS parser buffer overflow in token scanner
A buffer overflow vulnerability in Ghostscript's parser function was reported. A specially crafted postscript file could result in the execution of arbitrary code if opened or printed (i.e. via CUPS). Note that stack protections in the compiler render this into nothing more than a denial of service. This has been corrected in upstream Ghostscript 8.71; at least 8.64 and 8.70 are affected by this issue. Testing of Ghostscript 8.15 shows it does not suffer from this flaw.
Acknowledgements:
Red Hat would like to thank Rodrigo Rubira Branco of Check Point Vulnerability Discovery Team for responsibly reporting this issue.
Discussion:
This issue does not affect Fedora 11 or higher as they provide Ghostscript 8.71.
This i
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/39753http://secunia.com/advisories/40580http://www.checkpoint.com/defense/advisories/public/2010/cpai-10-May.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:102http://www.securityfocus.com/archive/1/511243/100/0/threadedhttp://www.securityfocus.com/bid/40103http://www.securitytracker.com/id?1024003http://www.ubuntu.com/usn/USN-961-1http://www.vupen.com/english/advisories/2010/1138http://www.vupen.com/english/advisories/2010/1195http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/39753http://secunia.com/advisories/40580http://www.checkpoint.com/defense/advisories/public/2010/cpai-10-May.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:102http://www.securityfocus.com/archive/1/511243/100/0/threadedhttp://www.securityfocus.com/bid/40103http://www.securitytracker.com/id?1024003http://www.ubuntu.com/usn/USN-961-1http://www.vupen.com/english/advisories/2010/1138http://www.vupen.com/english/advisories/2010/1195
2010-05-12
Published