Overview
The TrueType bytecode interpreter which is a part of Ghostscript is prone to heap corruption.
Description
Ghostscript includes a TrueType bytecode interpreter which is prone to an off by one bug which causes heap corruption. Further details can be found in the Ghostscript Bug #691044, Ghostscript r10602 commit statement and Toucan System's TSSA-2010-01 advisory. |
Impact
An attacker may use a specially crafted document with a malformed TrueType font to cause a denial of service condition or execute arbitrary code. |
Solution
Upgrade to Ghostscript 8.71 or newer. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Jonathan Brossard for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2009-3743 |
Severity Metric: | 0.45 |
Date Public: | 2010-08-24 |
Date First Published: | 2010-08-24 |
Date Last Updated: | 2010-12-06 15:32 UTC |
Document Revision: | 35 |