CVE-2008-6679: Buffer Overflow
Published Dec 22, 2008
·Updated
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
Affected Software
2 affected componentsFixes available
redhat/ghostscript<0:8.15.2-9.4.el5_3.7
0:8.15.2-9.4.el5_3.7
Ghostscript Ghostscript=8.62
Event History
Dec 22, 2008
CVE Published
via Red Hat·12:00 AM
Apr 1, 2009
Data Sourced
via Red Hat·07:16 PM
DescriptionSeverityAffected Software
Apr 8, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6679?
CVE-2008-6679 has been classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2008-6679?
To fix CVE-2008-6679, update Ghostscript to version 8.15.2-9.4.el5_3.7 or later.
3
What types of attacks are possible with CVE-2008-6679?
CVE-2008-6679 allows attackers to cause denial of service or potentially execute arbitrary code via crafted Postscript files.
4
Which versions of Ghostscript are affected by CVE-2008-6679?
CVE-2008-6679 affects Ghostscript version 8.62 and possibly earlier versions.
5
Can CVE-2008-6679 impact systems other than Red Hat?
Yes, CVE-2008-6679 could potentially impact any system using the vulnerable versions of Ghostscript.