This application requires Javascript for optimal performance.

Ghostscript.PS.Seticcspace.Buffer.Overflow

Release Date

Jun 24, 2008

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a buffer-overflow vulnerability in Ghostscript.

The vulnerability is caused by a boundary-check error when the vulnerable software opens a crafted .ps file. A successful exploit allows a remote attacker to execute arbitrary code.

Affected Products

Ghostscript 8.61 and earlier.

Recommended Actions

The vendor has issued a fix. Please refer to the vendor's website for the suggested workaround:
http://www.ghostscript.com/awki

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-0411

Reference/s

http://www.securityfocus.com/bid/28017 (BugTraq)

Reference: VID-15678