CVE-2009-4270
Publication date 21 December 2009
Last updated 24 July 2024
Ubuntu priority
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
Status
Package | Ubuntu Release | Status |
---|---|---|
ghostscript | ||
gs-afpl | ||
gs-esp | ||
gs-gpl | ||
Notes
mdeslaur
Jaunty and over are a DoS because of FORTIFY_SOURCE dapper and hardy have the vulnerable code in gsmisc.c, but it's not called from cups_put_params() in gdevcups.c.