search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Ghostscript crashes when passing a null ipsp->ip value to the gs_type2_interpret function

Vulnerability Note VU#538191

Original Release Date: 2010-10-12 | Last Revised: 2010-11-30

Overview

The gs_type2_interpret function which is a part of Ghostscript is prone to denial-of-service conditions.

Description

Ghostscript contains a function called gs_type2_interpret which is not performing null value error checking. A specially crafted document can cause Ghostscript to deference a null pointer, causing a denial-of-service condition.

Impact

An attacker may use a specially crafted document to cause a denial-of-service condition.

Solution

Upgrade

According to the vendor's release notes this has been fixed in revision 10590.

Vendor Information

538191
 

Artifex Software, Inc. Affected

Notified:  July 29, 2010 Updated: October 12, 2010

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Jonathan Brossard at P1 Code Security for reporting this vulnerability.

This document was written by Michael Orlando.

Other Information

CVE IDs: None
Severity Metric: 0.36
Date Public: 2010-01-06
Date First Published: 2010-10-12
Date Last Updated: 2010-11-30 20:21 UTC
Document Revision: 23

Sponsored by CISA.