CVE-2010-1628
Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.04% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- artifex/gpl ghostscript
- Source
- secalert@redhat.com
References
- http://bugs.ghostscript.com/show_bug.cgi?id=691295
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
- http://seclists.org/fulldisclosure/2010/May/134Exploit
- http://secunia.com/advisories/39753Vendor Advisory
- http://secunia.com/advisories/40580Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201412-17.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:134
- http://www.openwall.com/lists/oss-security/2010/05/12/1Exploit
- http://www.openwall.com/lists/oss-security/2010/05/18/7Exploit
- http://www.securityfocus.com/archive/1/511243/100/0/threaded
- http://www.securityfocus.com/bid/40107Exploit
- http://www.ubuntu.com/usn/USN-961-1
- http://www.vupen.com/english/advisories/2010/1138Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/ghostscript/+bug/546009Exploit
- http://bugs.ghostscript.com/show_bug.cgi?id=691295
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
- http://seclists.org/fulldisclosure/2010/May/134Exploit
- http://secunia.com/advisories/39753Vendor Advisory
- http://secunia.com/advisories/40580Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201412-17.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:134
- http://www.openwall.com/lists/oss-security/2010/05/12/1Exploit
- http://www.openwall.com/lists/oss-security/2010/05/18/7Exploit
- http://www.securityfocus.com/archive/1/511243/100/0/threaded
- http://www.securityfocus.com/bid/40107Exploit
- http://www.ubuntu.com/usn/USN-961-1
- http://www.vupen.com/english/advisories/2010/1138Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/ghostscript/+bug/546009Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.