CVE-2008-0411

Ghostscript < 8.61 - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Will Drewry · cremotelinux
https://www.exploit-db.com/exploits/31309

Scores

EPSS 0.1531
EPSS Percentile 94.6%

Details

CWE
CWE-119
Status published
Products (4)
ghostscript/ghostscript 0
ghostscript/ghostscript 8.0.1
ghostscript/ghostscript 8.15
ghostscript/ghostscript < 8.61
Published Feb 28, 2008
Tracked Since Feb 18, 2026