CVE-2010-4820 – ghostscript: CWD included in the default library search path
https://notcve.org/view.php?id=CVE-2010-4820
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055. Vulnerabilidad no especificada en Ghostscript 8.62 permite a atacantes remotos ejecutar código PostScript arbitrario a través de un fichero troyano de la librería Postscript en Encoding/ bajo el directorio de trabajo actual, una vulnerabilidad diferente a CVE-2010-2055. • http://bugs.ghostscript.com/show_bug.cgi?id=691339 http://rhn.redhat.com/errata/RHSA-2012-0095.html http://rhn.redhat.com/errata/RHSA-2012-0096.html http://www.openwall.com/lists/oss-security/2012/01/04/7 http://www.securityfocus.com/archive/1/511433 http://www.securityfocus.com/bid/51847 https://bugzilla.redhat.com/show_bug.cgi?id=599564 https://bugzilla.redhat.com/show_bug.cgi?id=771853 https://access.redhat.com/security/cve/CVE-2010-4820 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2009-4270
https://notcve.org/view.php?id=CVE-2009-4270
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver. Desbordamiento de búfer basado en pila en la función errprintf en base/gsmisc.c en ghostscript v8.64 hasta v8.70 permite a atacantes remotos provocar una denegación de servicio (caída) y probablemente ejecutar código de su elección mediante un fichero PDF modificado, como inicialmente se reportó por código de registro de depuración en gdevcups.c en el controlador de salida CUPS. • http://bugs.ghostscript.com/show_bug.cgi?id=690829 http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html http://osvdb.org/61140 http://secunia.com/advisories/37851 http://secunia.com/advisories/40580 http://security.gentoo.org/glsa/glsa-201412-17.xml http://www.mandriva.com/security/advisories?name=MDVSA-2010:134 http://www.mandriva.com/security/advisories?name=MDVSA-2010:135 http://www.openwall.com/lists/oss-security/2009/12/18/1 http://www.openwall • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-0792 – argyllcms: Incomplete fix for CVE-2009-0583
https://notcve.org/view.php?id=CVE-2009-0792
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583. Múltiples desbordamientos de entero en icc.c en el International Color Consortium (ICC) Format library (también conocido como icclib), como lo utilizado en Ghostscript v8.64 y versiones anteriores y Argyll Color Management System (CMS) v1.0.3 y versiones anteriores, permite a atacantes dependientes de contexto provocar una denegación de servicio (desbordamiento de búfer basado en montículo y caída de aplicación) o posiblemente ejecutar código de su elección utilizado un fichero de dispositivo para una petición de traducción que opera en un fichero de imagen manipulado y tiene como objetivo un determinado "espacio de color nativo," relacionado con un perfil ICC en un (1) PostScript o (2) fichero PDF file with embedded image con imágenes embebidas. NOTA: esta cuestión existe debido a una modificación inicial imcompleta de CVE-2009-0583. • http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html http://secunia.com/advisories/34373 http://secunia.com/advisories/34667 http://secunia.com/advisories/34711 http://secunia.com/advisories/34726 http://secunia.com/advisories/34729 http://secunia.com/advisories/34732 http://secunia.com/advisories/35416 http://secunia.com/advisories/35559 http://secunia.com/advisories/35569 http://sec • CWE-189: Numeric Errors •
CVE-2009-0196 – ghostscript: Missing boundary check in Ghostscript's jbig2dec library
https://notcve.org/view.php?id=CVE-2009-0196
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value. Desbordamiento de entero en la función big2_decode_symbol_dict (jbig2_symbol_dict.c) en la librería de decodificación JBIG2 (jbig2dec) en Ghostscript 8.64 y posiblemente versiones anteriores, permite a atacantes remotos ejecutar código de su elección mediante un fichero PDF que contenga un segmento de diccionario de símbolos JBIG2 con un valor grande de longitud de repetición(run length). • http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html http://osvdb.org/53492 http://secunia.com/advisories/34292 http://secunia.com/advisories/34667 http://secunia.com/advisories/34729 http://secunia.com/advisories/34732 http://secunia.com/advisories/35416 http://secunia.com/advisories/35559 http://secunia.com/advisories/35569 http://secunia.com/secunia_research/2009-21 http://secur • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2007-6725 – ghostscript: DoS (crash) in CCITTFax decoding filter
https://notcve.org/view.php?id=CVE-2007-6725
The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function. El filtro de decodificar CCITTFax en Ghostscript v8.60, v8.61, y posiblemente otras versiones, permite a atacantes remotos provocar una denegación de servicio (caída) y posiblemente ejecución de código arbitrario a través de un fichero PDF modificado que provoca un desbordamiento inferior de búfer en la función cf_decode_2d. • http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html http://secunia.com/advisories/34726 http://secunia.com/advisories/34729 http://secunia.com/advisories/34732 http://secunia.com/advisories/35416 http://secunia.com/advisories/35559 http://secunia.com/advisories/35569 http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1 http://support.avaya.com/elmodocs2/security/ASA-2009-155.htm http://wiki.rpath.com/Advisories:rPSA-2009-0060 http://www. • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •