| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.801411 |
| Kategorie: | Buffer overflow |
| Titel: | Ghostscript 'iscan.c' PDF Handling Remote Buffer Overflow Vulnerability |
| Zusammenfassung: | Check for the Version of Ghostscript |
| Beschreibung: | Overview: This host is installed with Ghostscript and is prone to buffer overflow vulnerability. Vulnerability Insight: The flaw is due to improper bounds checking by 'iscan.c' when processing malicious 'PDF' files, which leads to open a specially-crafted PDF file. Impact: Successful exploitation allows the attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name. Impact Level: Application Affected Software/OS: Ghostscript version 8.64 and prior Fix: Upgrade to Ghostscript version 8.71 or later, For updates refer to http://www.ghostscript.com/ References: http://secunia.com/advisories/40580 http://xforce.iss.net/xforce/xfdb/60380 |
| Querverweis: |
BugTraq ID: 41593 Common Vulnerability Exposure (CVE) ID: CVE-2009-4897 http://www.mandriva.com/security/advisories?name=MDVSA-2010:134 http://www.mandriva.com/security/advisories?name=MDVSA-2010:135 http://www.ubuntu.com/usn/USN-961-1 http://www.securityfocus.com/bid/41593 http://www.osvdb.org/66277 http://secunia.com/advisories/40580 XForce ISS Database: ghostscript-iscan-bo(60380) http://xforce.iss.net/xforce/xfdb/60380 |
| Copyright | Copyright (c) 2010 Greenbone Networks GmbH |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|