First published: Tue Apr 14 2009(Updated: )
Ghostscript is a set of software that provides a PostScript interpreter, a<br>set of C procedures (the Ghostscript library, which implements the graphics<br>capabilities in the PostScript language) and an interpreter for Portable<br>Document Format (PDF) files.<br>It was discovered that the Red Hat Security Advisory RHSA-2009:0345 did not<br>address all possible integer overflow flaws in Ghostscript's International<br>Color Consortium Format library (icclib). Using specially-crafted ICC<br>profiles, an attacker could create a malicious PostScript or PDF file with<br>embedded images that could cause Ghostscript to crash or, potentially,<br>execute arbitrary code when opened. (CVE-2009-0792)<br>A buffer overflow flaw and multiple missing boundary checks were found in<br>Ghostscript. An attacker could create a specially-crafted PostScript or PDF<br>file that could cause Ghostscript to crash or, potentially, execute<br>arbitrary code when opened. (CVE-2008-6679, CVE-2007-6725, CVE-2009-0196)<br>Red Hat would like to thank Alin Rad Pop of Secunia Research for<br>responsibly reporting the CVE-2009-0196 flaw.<br>Users of ghostscript are advised to upgrade to these updated packages,<br>which contain backported patches to correct these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ghostscript | <8.15.2-9.4.el5_3.7 | 8.15.2-9.4.el5_3.7 |
redhat/ghostscript | <8.15.2-9.4.el5_3.7 | 8.15.2-9.4.el5_3.7 |
redhat/ghostscript-devel | <8.15.2-9.4.el5_3.7 | 8.15.2-9.4.el5_3.7 |
redhat/ghostscript-devel | <8.15.2-9.4.el5_3.7 | 8.15.2-9.4.el5_3.7 |
redhat/ghostscript-gtk | <8.15.2-9.4.el5_3.7 | 8.15.2-9.4.el5_3.7 |
redhat/ghostscript-gtk | <8.15.2-9.4.el5_3.7 | 8.15.2-9.4.el5_3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.