Back

HIGH

ghostscript: Missing boundary check in Ghostscript's jbig2dec library

Published Apr 16, 2009

Description

Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published Apr 16, 2009
Updated Aug 7, 2024
Reserved Jan 20, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Apr 8, 2009