Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ghostscript | Jul 30, 2024 | Jul 22, 2010 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Oct 30, 2017 | Jul 22, 2010 |
| Ghostscript | — | Upgrade to Ghostscript version 8.70 | Oct 10, 2018 | Jul 22, 2010 |
| Suse | — | Upgrade ghostscript-fonts-stdUpgrade ghostscript-libraryUpgrade ghostscript-fonts-otherUpgrade libgimpprintUpgrade ghostscript-x11Upgrade ghostscript-fonts-rusUpgrade ghostscript-omni | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgs8 | Nov 8, 2024 | Jul 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub