Ghostscript TrueType Bytecode Interpreter Heap-Based Memory Corruption Vulnerability
BID:42640
Info
Ghostscript TrueType Bytecode Interpreter Heap-Based Memory Corruption Vulnerability
| Bugtraq ID: | 42640 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3743 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2010 12:00AM |
| Updated: | Dec 16 2014 12:55AM |
| Credit: | Jonathan Brossard |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Ghostscript Ghostscript 8.15.2 Ghostscript Ghostscript 8.0.1 Ghostscript Ghostscript 5.50 Ghostscript Ghostscript 8.70 Ghostscript Ghostscript 8.64 Ghostscript Ghostscript 8.61 Ghostscript Ghostscript 8.60 Ghostscript Ghostscript 8.57 Ghostscript Ghostscript 8.56 Ghostscript Ghostscript 8.54 Ghostscript Ghostscript 8.15 Ghostscript Ghostscript 7.07 Ghostscript Ghostscript 7.05 Ghostscript Ghostscript 0 Gentoo Linux Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Aladdin Enterprises Ghostscript 8.50 Aladdin Enterprises Ghostscript 8.0 1 Aladdin Enterprises Ghostscript 7.0 7 Aladdin Enterprises Ghostscript 7.0 6 Aladdin Enterprises Ghostscript 7.0 5 Aladdin Enterprises Ghostscript 7.0 4 Aladdin Enterprises Ghostscript 6.53 Aladdin Enterprises Ghostscript 6.52 Aladdin Enterprises Ghostscript 6.51 Aladdin Enterprises Ghostscript 5.50.8 _7 Aladdin Enterprises Ghostscript 5.50.8 Aladdin Enterprises Ghostscript 5.50 Aladdin Enterprises Ghostscript 5.10.16 Aladdin Enterprises Ghostscript 5.10.15 Aladdin Enterprises Ghostscript 5.10.12 cl Aladdin Enterprises Ghostscript 5.10.10 mdk Aladdin Enterprises Ghostscript 5.10.10 -1 mdk Aladdin Enterprises Ghostscript 5.10.10 -1 Aladdin Enterprises Ghostscript 5.10.10 Aladdin Enterprises Ghostscript 5.10 cl Aladdin Enterprises Ghostscript 4.3.2 Aladdin Enterprises Ghostscript 4.3 |
| Not Vulnerable: |
Ghostscript Ghostscript 8.71 |
Discussion
Ghostscript TrueType Bytecode Interpreter Heap-Based Memory Corruption Vulnerability
Ghostscript is prone to a memory-corruption vulnerability in its TrueType bytecode interpreter.
An attacker can exploit this issue to execute arbitrary code. Failed exploit attempts will likely cause denial-of-service conditions.
Versions prior to Ghostscript 8.71 are vulnerable.
Ghostscript is prone to a memory-corruption vulnerability in its TrueType bytecode interpreter.
An attacker can exploit this issue to execute arbitrary code. Failed exploit attempts will likely cause denial-of-service conditions.
Versions prior to Ghostscript 8.71 are vulnerable.
Exploit / POC
Ghostscript TrueType Bytecode Interpreter Heap-Based Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Ghostscript TrueType Bytecode Interpreter Heap-Based Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Ghostscript TrueType Bytecode Interpreter Heap-Based Memory Corruption Vulnerability
References:
References:
- Ghostscript Homepage (Ghostscript)
- ghostscript security update (RHSA-2012-0095) (Avaya)
- TSSA-2010-01 Ghostscript library Ins_MINDEX() integer overflow and heap corrupt (Advisories Toucan-System
) - Vulnerability Note VU#644319 Ghostscript Heap Corruption in TrueType bytecode in (US-CERT)