Lucene search

K
nvd[email protected]NVD:CVE-2009-0196
HistoryApr 16, 2009 - 3:12 p.m.

CVE-2009-0196

2009-04-1615:12:57
CWE-119
web.nvd.nist.gov
6

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.139

Percentile

95.7%

Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.

Affected configurations

Nvd
Node
ghostscriptghostscriptRange≀8.64
OR
ghostscriptghostscriptMatch0
OR
ghostscriptghostscriptMatch5.50
OR
ghostscriptghostscriptMatch7.07
OR
ghostscriptghostscriptMatch8.0.1
OR
ghostscriptghostscriptMatch8.15
OR
ghostscriptghostscriptMatch8.15.2
OR
ghostscriptghostscriptMatch8.54
OR
ghostscriptghostscriptMatch8.56
OR
ghostscriptghostscriptMatch8.57
OR
ghostscriptghostscriptMatch8.60
OR
ghostscriptghostscriptMatch8.61
OR
ghostscriptghostscriptMatch8.62
OR
ghostscriptghostscriptMatch8.63

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.139

Percentile

95.7%