CVE-2009-0196
16.04.2009, 15:12
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.Enginsight
Vendor | Product | Version |
---|---|---|
ghostscript | ghostscript | 𝑥 ≤ 8.64 |
ghostscript | ghostscript | 5.50 |
ghostscript | ghostscript | 7.07 |
ghostscript | ghostscript | 8.0.1 |
ghostscript | ghostscript | 8.15 |
ghostscript | ghostscript | 8.15.2 |
ghostscript | ghostscript | 8.54 |
ghostscript | ghostscript | 8.56 |
ghostscript | ghostscript | 8.57 |
ghostscript | ghostscript | 8.60 |
ghostscript | ghostscript | 8.61 |
ghostscript | ghostscript | 8.62 |
ghostscript | ghostscript | 8.63 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ghostscript |
| ||||||||||||
jbig2dec |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ghostscript |
| ||||||||||||
gs-afpl |
| ||||||||||||
gs-esp |
| ||||||||||||
gs-gpl |
|
Common Weakness Enumeration
References