HIGH
CVE-2009-4270 ghostscript buffer overflow in cups output driver
Published Dec 21, 2009
9.3
HIGHCVSS 2.0
EPSS 6.90%
Description
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
Affected products
No data.
OR
- 8.64
- 8.70
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of ghostscript as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Weaknesses (1)
References (17)
- http://bugs.ghostscript.com/show_bug.cgi?id=690829 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/61140 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/37851 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/40580 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201412-17.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:134 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:135 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2009/12/18/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/12/18/2 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/37410 vdb-entryx_refsource_BIDExploit
- http://www.ubuntu.com/usn/USN-961-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/3597 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-4270 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=540760 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-4270
- https://www.cve.org/CVERecord?id=CVE-2009-4270
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 21, 2009
Updated Aug 7, 2024
Reserved Dec 10, 2009
Link CVE-2009-4270
CISA Vulnrichment
Updated n/a