CVE-2009-0196: Buffer Overflow
Heap-based buffer overflow in the big2decodesymboldict function (jbig2symboldict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0196?
CVE-2009-0196 is considered critical due to its potential for remote attackers to execute arbitrary code.
How do I fix CVE-2009-0196?
To fix CVE-2009-0196, upgrade Ghostscript to a version later than 8.64 that addresses this vulnerability.
What versions of Ghostscript are affected by CVE-2009-0196?
CVE-2009-0196 affects Ghostscript versions up to and including 8.64.
What kind of attack does CVE-2009-0196 enable?
CVE-2009-0196 allows remote code execution through specially crafted PDF files containing a JBIG2 symbol dictionary.
Is CVE-2009-0196 a known vulnerability?
Yes, CVE-2009-0196 is a documented vulnerability identified in 2009 within the Ghostscript JBIG2 decoding library.