Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ghostscript | Jul 30, 2024 | Feb 28, 2008 |
| Freebsd | — | Upgrade ghostscript-gplUpgrade ghostscript-gpl-nox11 | Dec 10, 2025 | Mar 5, 2008 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gnu.Upgrade app-text/ghostscript-esp.Upgrade app-text/ghostscript-gpl. | Oct 30, 2017 | Feb 28, 2008 |
| Oracle_linux | — | Upgrade ghostscript-gtkUpgrade ghostscript-develUpgrade ghostscript | Oct 16, 2024 | Feb 28, 2008 |
| Suse | — | Upgrade ghostscript-x11Upgrade ghostscript-ijs-develUpgrade libgimpprintUpgrade suse-releaseUpgrade ghostscript-omniUpgrade ghostscript-fonts-rusUpgrade ghostscript-libraryUpgrade ghostscript-servUpgrade ghostscript-fonts-otherUpgrade libgimpprint-develUpgrade ghostscript-fonts-std | Feb 17, 2015 | Feb 28, 2008 |
| Ubuntu | — | Upgrade libgs8Upgrade gs-gplUpgrade gs-esp | Nov 8, 2024 | Feb 28, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub