Lucene search

K
redosRedosROS-20240826-06
HistoryAug 26, 2024 - 12:00 a.m.

ROS-20240826-06

2024-08-2600:00:00
redos.red-soft.ru
28
ghostscript
buffer overflow
vulnerability
denial of service
unix
arbitrary code
execution

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

8.7

Confidence

High

A vulnerability in the pdf_base_font_alloc() function of the Ghostscript document processing, conversion, and generation software suite is related to a buffer overflow resulting from an incorrect buffer overflow.
Ghostscript document generation software suite is related to a buffer overflow caused by incorrect pointer scaling (".F" PRI_INTPTR).
pointer scaling (".F" PRI_INTPTR). Exploitation of the vulnerability could allow an attacker,
acting remotely, to execute arbitrary code or cause a denial of service

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64ghostscript< 9.52-9UNKNOWN

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

8.7

Confidence

High