SUSE-SA:2008:010Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00009.html CVE-2008-0411
Ghostscript 8.0.1/8.15 - 'zseticcspace()' Remote Buffer Overflow
Record summary
CVE-2008-0411 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGhostscript 8.0.1/8.15 - 'zseticcspace()' Remote Buffer OverflowExploitDB exploitby Will DrewryNot analyzed1 file
References
Showing 12 of 28scary.beasts.org
http://scary.beasts.org/security/CESA-2008-001.html 29101Third-party advisory
http://secunia.com/advisories/29101 29103Third-party advisory
http://secunia.com/advisories/29103 29112Third-party advisory
http://secunia.com/advisories/29112 29135Third-party advisory
http://secunia.com/advisories/29135 29147Third-party advisory
http://secunia.com/advisories/29147 29154Third-party advisory
http://secunia.com/advisories/29154 29169Third-party advisory
http://secunia.com/advisories/29169 29196Third-party advisory
http://secunia.com/advisories/29196 29314Third-party advisory
http://secunia.com/advisories/29314 29768Third-party advisory
http://secunia.com/advisories/29768