Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-3743
Description:Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Test IDs: 1.3.6.1.4.1.25623.1.0.801269  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-3743
Bugtraq: 20101125 TSSA-2010-01 Ghostscript library Ins_MINDEX() integer overflow and heap corruption (Google Search)
http://www.securityfocus.com/archive/1/514892/100/0/threaded
CERT/CC vulnerability note: VU#644319
http://www.kb.cert.org/vuls/id/644319
http://security.gentoo.org/glsa/glsa-201412-17.xml
http://www.kb.cert.org/vuls/id/JALR-87YGN8
RedHat Security Advisories: RHSA-2012:0095
https://rhn.redhat.com/errata/RHSA-2012-0095.html
http://www.securitytracker.com/id?1024785




© 1998-2021 E-Soft Inc. All rights reserved.