CVE Vulnerabilities

CVE-2009-3743

Published: Aug 26, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
Afpl_ghostscriptArtifex6.0 (including)6.0 (including)
Afpl_ghostscriptArtifex6.01 (including)6.01 (including)
Afpl_ghostscriptArtifex6.50 (including)6.50 (including)
Afpl_ghostscriptArtifex7.00 (including)7.00 (including)
Afpl_ghostscriptArtifex7.03 (including)7.03 (including)
Afpl_ghostscriptArtifex7.04 (including)7.04 (including)
Afpl_ghostscriptArtifex8.00 (including)8.00 (including)
Afpl_ghostscriptArtifex8.11 (including)8.11 (including)
Afpl_ghostscriptArtifex8.12 (including)8.12 (including)
Afpl_ghostscriptArtifex8.13 (including)8.13 (including)
Afpl_ghostscriptArtifex8.14 (including)8.14 (including)
Afpl_ghostscriptArtifex8.50 (including)8.50 (including)
Afpl_ghostscriptArtifex8.51 (including)8.51 (including)
Afpl_ghostscriptArtifex8.52 (including)8.52 (including)
Afpl_ghostscriptArtifex8.53 (including)8.53 (including)
Afpl_ghostscriptArtifex8.54 (including)8.54 (including)
Ghostscript_fontsArtifex6.0 (including)6.0 (including)
Ghostscript_fontsArtifex8.11 (including)8.11 (including)
Gpl_ghostscriptArtifex*8.70 (including)
Gpl_ghostscriptArtifex8.01 (including)8.01 (including)
Gpl_ghostscriptArtifex8.15 (including)8.15 (including)
Gpl_ghostscriptArtifex8.50 (including)8.50 (including)
Gpl_ghostscriptArtifex8.51 (including)8.51 (including)
Gpl_ghostscriptArtifex8.54 (including)8.54 (including)
Gpl_ghostscriptArtifex8.56 (including)8.56 (including)
Gpl_ghostscriptArtifex8.57 (including)8.57 (including)
Gpl_ghostscriptArtifex8.60 (including)8.60 (including)
Gpl_ghostscriptArtifex8.61 (including)8.61 (including)
Gpl_ghostscriptArtifex8.62 (including)8.62 (including)
Gpl_ghostscriptArtifex8.63 (including)8.63 (including)
Gpl_ghostscriptArtifex8.64 (including)8.64 (including)
Red Hat Enterprise Linux 5RedHatghostscript-0:8.70-6.el5_7.6*
Red Hat Enterprise Linux 6RedHatghostscript-0:8.70-11.el6_2.6*
GhostscriptUbuntuhardy*
GhostscriptUbuntujaunty*
GhostscriptUbuntukarmic*
Gs-afplUbuntudapper*
Gs-espUbuntudapper*
Gs-gplUbuntudapper*

References