CVE-2009-3743: Buffer Overflow
Off-by-one error in the InsMINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3743?
CVE-2009-3743 is considered to have a high severity due to the potential for remote code execution and denial of service through exploitation.
How do I fix CVE-2009-3743?
To fix CVE-2009-3743, upgrade Ghostscript to version 8.71 or later, which resolves this vulnerability.
What causes CVE-2009-3743?
CVE-2009-3743 is caused by an off-by-one error in the Ins_MINDEX function within Ghostscript's TrueType bytecode interpreter.
Which versions of Ghostscript are affected by CVE-2009-3743?
CVE-2009-3743 affects multiple Ghostscript versions prior to 8.71, including 7.00 and 8.54.
Can CVE-2009-3743 lead to data breaches?
Yes, CVE-2009-3743 can lead to data breaches as it allows an attacker to execute arbitrary code through specially crafted TrueType fonts.