Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ghostscriptUpgrade ghostscript-gtkUpgrade ghostscript-devel | Dec 1, 2016 | Apr 16, 2009 |
| Debian | — | Upgrade ghostscript | Jul 30, 2024 | Apr 16, 2009 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Oct 30, 2017 | Apr 16, 2009 |
| Oracle_linux | — | Upgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-gtk | Oct 16, 2024 | Apr 16, 2009 |
| Suse | — | Upgrade libgimpprint-develUpgrade ghostscript-fonts-rusUpgrade ghostscript-ijs-develUpgrade ghostscript-omniUpgrade ghostscript-develUpgrade libgimpprintUpgrade ghostscript-fonts-otherUpgrade ghostscript-x11Upgrade ghostscript-libraryUpgrade ghostscript-fonts-std | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gs-gplUpgrade libgs8Upgrade gs-esp | Nov 8, 2024 | Apr 16, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub