http://secunia.com/secunia_research/2009-21/
Description of Vulnerability
Secunia Research has discovered a vulnerability in Ghostscript, which can be exploited by malicious people to potentially compromise a user's system.
The vulnerability is caused due to a boundary error in the included jbig2dec library while decoding JBIG2 symbol dictionary segments. This can be exploited to cause a heap-based buffer overflow via a specially crafted PDF file.
Successful exploitation may allow execution of arbitrary code.
Affected Software
* Ghostscript version 8.64
NOTE: Other versions may also be affected.
Solution
Do not process untrusted PDF files.
Credits
Discovered by Alin Rad Pop, Secunia Research
No comments:
Post a Comment