Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Afpl_ghostscript | Artifex | 6.0 (including) | 6.0 (including) |
Afpl_ghostscript | Artifex | 6.01 (including) | 6.01 (including) |
Afpl_ghostscript | Artifex | 6.50 (including) | 6.50 (including) |
Afpl_ghostscript | Artifex | 7.00 (including) | 7.00 (including) |
Afpl_ghostscript | Artifex | 7.03 (including) | 7.03 (including) |
Afpl_ghostscript | Artifex | 7.04 (including) | 7.04 (including) |
Afpl_ghostscript | Artifex | 8.00 (including) | 8.00 (including) |
Afpl_ghostscript | Artifex | 8.11 (including) | 8.11 (including) |
Afpl_ghostscript | Artifex | 8.12 (including) | 8.12 (including) |
Afpl_ghostscript | Artifex | 8.13 (including) | 8.13 (including) |
Afpl_ghostscript | Artifex | 8.14 (including) | 8.14 (including) |
Afpl_ghostscript | Artifex | 8.50 (including) | 8.50 (including) |
Afpl_ghostscript | Artifex | 8.51 (including) | 8.51 (including) |
Afpl_ghostscript | Artifex | 8.52 (including) | 8.52 (including) |
Afpl_ghostscript | Artifex | 8.53 (including) | 8.53 (including) |
Afpl_ghostscript | Artifex | 8.54 (including) | 8.54 (including) |
Ghostscript_fonts | Artifex | 6.0 (including) | 6.0 (including) |
Ghostscript_fonts | Artifex | 8.11 (including) | 8.11 (including) |
Gpl_ghostscript | Artifex | * | 8.70 (including) |
Gpl_ghostscript | Artifex | 8.01 (including) | 8.01 (including) |
Gpl_ghostscript | Artifex | 8.15 (including) | 8.15 (including) |
Gpl_ghostscript | Artifex | 8.50 (including) | 8.50 (including) |
Gpl_ghostscript | Artifex | 8.51 (including) | 8.51 (including) |
Gpl_ghostscript | Artifex | 8.54 (including) | 8.54 (including) |
Gpl_ghostscript | Artifex | 8.56 (including) | 8.56 (including) |
Gpl_ghostscript | Artifex | 8.57 (including) | 8.57 (including) |
Gpl_ghostscript | Artifex | 8.60 (including) | 8.60 (including) |
Gpl_ghostscript | Artifex | 8.61 (including) | 8.61 (including) |
Gpl_ghostscript | Artifex | 8.62 (including) | 8.62 (including) |
Gpl_ghostscript | Artifex | 8.63 (including) | 8.63 (including) |
Gpl_ghostscript | Artifex | 8.64 (including) | 8.64 (including) |
Red Hat Enterprise Linux 5 | RedHat | ghostscript-0:8.70-6.el5_7.6 | * |
Red Hat Enterprise Linux 6 | RedHat | ghostscript-0:8.70-11.el6_2.6 | * |
Ghostscript | Ubuntu | hardy | * |
Ghostscript | Ubuntu | jaunty | * |
Ghostscript | Ubuntu | karmic | * |
Gs-afpl | Ubuntu | dapper | * |
Gs-esp | Ubuntu | dapper | * |
Gs-gpl | Ubuntu | dapper | * |