The TrueType bytecode interpreter which is a part of Ghostscript is prone to heap corruption.
Ghostscript includes a TrueType bytecode interpreter which is prone to an off by one bug which causes heap corruption. Further details can be found in the Ghostscript Bug #691044, Ghostscript r10602 commit statement and Toucan System's TSSA-2010-01 advisory.
An attacker may use a specially crafted document with a malformed TrueType font to cause a denial of service condition or execute arbitrary code.
Upgrade to Ghostscript 8.71 or newer.
Thanks to Jonathan Brossard for reporting this vulnerability.
This document was written by Jared Allar.
|Date First Published:
|Date Last Updated:
|2010-12-06 15:32 UTC