CVE-2010-1628

EUVD-2010-1651
Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
artifexgpl_ghostscript
8.64
artifexgpl_ghostscript
8.70
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ghostscript
bookworm
10.0.0~dfsg-11+deb12u4
fixed
bookworm (security)
10.0.0~dfsg-11+deb12u5
fixed
bullseye
9.53.3~dfsg-7+deb11u7
fixed
bullseye (security)
9.53.3~dfsg-7+deb11u8
fixed
sid
10.04.0~dfsg-1
fixed
trixie
10.04.0~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ghostscript
dapper
dne
hardy
Fixed 8.61.dfsg.1-1ubuntu3.3
released
intrepid
ignored
jaunty
Fixed 8.64.dfsg.1-0ubuntu8.1
released
karmic
Fixed 8.70.dfsg.1-0ubuntu3.1
released
lucid
Fixed 8.71.dfsg.1-0ubuntu5.2
released
gs-afpl
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
gs-esp
dapper
not-affected
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
gs-gpl
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne