CVE-2010-1869
Ghostscript - '.PostScript' File Stack Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
Desbordamiento de búffer basado en el parseo de la función de GhostScript v8.70 y v8.64 permite a atacantes dependiendo del contexto ejecutar código de su elección a través de la manipulación del fichero PostScript.
David Srbecky discovered that Ghostscript incorrectly handled debug logging. It was discovered that Ghostscript incorrectly handled certain malformed files. Dan Rosenberg discovered that Ghostscript incorrectly handled certain recursive Postscript files. Rodrigo Rubira Branco and Dan Rosenberg discovered that Ghostscript incorrectly handled certain malformed Postscript files.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-05-10 CVE Reserved
- 2010-05-12 CVE Published
- 2010-07-18 First Exploit
- 2024-08-07 CVE Updated
- 2025-08-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (13)
| URL | Tag | Source |
|---|---|---|
| http://secunia.com/advisories/39753 | Third Party Advisory | |
| http://secunia.com/advisories/40580 | Third Party Advisory | |
| http://www.checkpoint.com/defense/advisories/public/2010/cpai-10-May.html | X_refsource_misc | |
| http://www.securityfocus.com/archive/1/511243/100/0/threaded | Mailing List | |
| http://www.securityfocus.com/bid/40103 | Vdb Entry | |
| http://www.securitytracker.com/id?1024003 | Vdb Entry | |
| http://www.vupen.com/english/advisories/2010/1138 | Vdb Entry | |
| http://www.vupen.com/english/advisories/2010/1195 | Vdb Entry |
| URL | Date | SRC |
|---|---|---|
| https://packetstorm.news/files/id/91955 | 2010-07-18 | |
| https://www.exploit-db.com/exploits/14406 | 2010-07-18 |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html | 2018-10-10 | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2010:102 | 2018-10-10 | |
| http://www.ubuntu.com/usn/USN-961-1 | 2018-10-10 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Artifex Search vendor "Artifex" | Gpl Ghostscript Search vendor "Artifex" for product "Gpl Ghostscript" | 8.64 Search vendor "Artifex" for product "Gpl Ghostscript" and version "8.64" | - |
Affected
| ||||||
| Artifex Search vendor "Artifex" | Gpl Ghostscript Search vendor "Artifex" for product "Gpl Ghostscript" | 8.70 Search vendor "Artifex" for product "Gpl Ghostscript" and version "8.70" | - |
Affected
| ||||||
