CVE-2015-3228: Integer Overflow
Integer overflow in the gsheapallocbytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of service (crash) via a crafted Postscript (ps) file, as demonstrated by using the ps2pdf command, which triggers an out-of-bounds read or write.
Other sources
Out-of-bounbds read and write has been reported in GhostScript package while processing a crafted .ps file.
Upstream bug: http://bugs.ghostscript.com/showbug.cgi?id=696041 Upstream commit that fixes this (as per reporter): http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ecc7a199e9307475c37fea0c44d24b85df814ead
Acknowledgements:
Red Hat would like to thank William Robinet of Conostix S.A. for reporting this issue.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3228?
CVE-2015-3228 has been rated as critical due to its potential to cause denial of service through integer overflow.
How do I fix CVE-2015-3228?
To fix CVE-2015-3228, upgrade Ghostscript to version 9.16 or later.
What versions of Ghostscript are affected by CVE-2015-3228?
Ghostscript versions 9.15 and earlier are affected by CVE-2015-3228.
Can CVE-2015-3228 be exploited remotely?
Yes, CVE-2015-3228 can be exploited remotely via a specially crafted Postscript file.
What type of attack is associated with CVE-2015-3228?
CVE-2015-3228 is associated with denial of service attacks due to an integer overflow exploit.