|
|
|
![]() |
Vulnerability Note VU#644319Ghostscript Heap Corruption in TrueType bytecode interpreterOverviewThe TrueType bytecode interpreter which is a part of Ghostscript is prone to heap corruption.I. DescriptionGhostscript includes a TrueType bytecode interpreter which is prone to an off by one bug which causes heap corruption. Further details can be found in the Ghostscript Bug #691044, Ghostscript r10602 commit statement and Toucan System's TSSA-2010-01 advisory.II. ImpactAn attacker may use a specially crafted document with a malformed TrueType font to cause a denial of service condition or execute arbitrary code.III. SolutionUpgrade to Ghostscript 8.71 or newer.Vendor Information
Referenceshttps://code.google.com/p/ghostscript/source/detail?r=10602&path=/trunk/gs/base/ttinterp.c Thanks to Jonathan Brossard for reporting this vulnerability. This document was written by Jared Allar.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||