REDHAT-BUG-613792: High severity ghostscript vulnerability
A memory corruption vulnerability caused by long names was discovered [1] in Ghostscript 8.64 and earlier. A specially crafted PDF file could result in the execution of arbitrary code if opened or printed (i.e. via CUPS).
This was corrected in upstream Ghostscript 8.70 [2], version 8.64 and previous are affected by this flaw (all the way back to Ghostscript 7.05).
References:
[1] http://bugs.ghostscript.com/showbug.cgi?id=690523 [2] http://svn.ghostscript.com/viewvc?view=rev&revision=9797
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-613792?
The severity of REDHAT-BUG-613792 is critical due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-613792?
To fix REDHAT-BUG-613792, upgrade to Ghostscript version 8.70 or newer.
What versions of Ghostscript are affected by REDHAT-BUG-613792?
Ghostscript versions up to and including 8.64 are affected by REDHAT-BUG-613792.
What type of vulnerability is REDHAT-BUG-613792?
REDHAT-BUG-613792 is a memory corruption vulnerability caused by long names in PDF files.
Can REDHAT-BUG-613792 be exploited through a crafted PDF file?
Yes, REDHAT-BUG-613792 can be exploited by opening or printing a specially crafted PDF file.