Lucene search

K
cveFlexeraCVE-2009-0196
HistoryApr 16, 2009 - 3:12 p.m.

CVE-2009-0196

2009-04-1615:12:57
CWE-119
flexera
web.nvd.nist.gov
45
cve-2009-0196
nvd
buffer overflow
jbig2
ghostscript
pdf
security
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.139

Percentile

95.7%

Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.

Affected configurations

Nvd
Node
ghostscriptghostscriptRange≀8.64
OR
ghostscriptghostscriptMatch0
OR
ghostscriptghostscriptMatch5.50
OR
ghostscriptghostscriptMatch7.07
OR
ghostscriptghostscriptMatch8.0.1
OR
ghostscriptghostscriptMatch8.15
OR
ghostscriptghostscriptMatch8.15.2
OR
ghostscriptghostscriptMatch8.54
OR
ghostscriptghostscriptMatch8.56
OR
ghostscriptghostscriptMatch8.57
OR
ghostscriptghostscriptMatch8.60
OR
ghostscriptghostscriptMatch8.61
OR
ghostscriptghostscriptMatch8.62
OR
ghostscriptghostscriptMatch8.63
VendorProductVersionCPE
ghostscriptghostscript8.15cpe:/a:ghostscript:ghostscript:8.15:::
ghostscriptghostscriptcpe:/a:ghostscript:ghostscript::::
ghostscriptghostscript0cpe:/a:ghostscript:ghostscript:0:::
ghostscriptghostscript8.54cpe:/a:ghostscript:ghostscript:8.54:::
ghostscriptghostscript8.57cpe:/a:ghostscript:ghostscript:8.57:::
ghostscriptghostscript8.0.1cpe:/a:ghostscript:ghostscript:8.0.1:::
ghostscriptghostscript8.62cpe:/a:ghostscript:ghostscript:8.62:::
ghostscriptghostscript8.15.2cpe:/a:ghostscript:ghostscript:8.15.2:::
ghostscriptghostscript8.63cpe:/a:ghostscript:ghostscript:8.63:::
ghostscriptghostscript8.61cpe:/a:ghostscript:ghostscript:8.61:::
Rows per page:
1-10 of 141

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.139

Percentile

95.7%