Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-1869
HistoryMay 12, 2010 - 12:00 a.m.

CVE-2010-1869

2010-05-1200:00:00
ubuntu.com
ubuntu.com
13

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.005

Percentile

76.7%

Stack-based buffer overflow in the parser function in GhostScript 8.70 and
8.64 allows context-dependent attackers to execute arbitrary code via a
crafted PostScript file.

Bugs

Notes

Author Note
mdeslaur reproducer doesn’t appear to work on dapper’s gs-esp stack protector makes this a DoS on karmic
OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchghostscript< 8.61.dfsg.1-1ubuntu3.3UNKNOWN
ubuntu9.04noarchghostscript< 8.64.dfsg.1-0ubuntu8.1UNKNOWN
ubuntu9.10noarchghostscript< 8.70.dfsg.1-0ubuntu3.1UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.005

Percentile

76.7%