Описание
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
A flaw was found in Artifex Ghostscript. An integer overflow vulnerability, which occurs when a program attempts to store a number in an integer variable that is too small to hold it, leads to a heap-based buffer overflow. This allows a local attacker to cause a Denial of Service (DoS) by processing a specially crafted document.
Отчет
This vulnerability is rated Moderate for Red Hat products. An integer overflow in Artifex Ghostscript's OCR processing, specifically in ocr_begin_page, can lead to a heap-based buffer overflow. This flaw could be triggered by processing a specially crafted document, potentially resulting in denial of service or arbitrary code execution.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | ghostscript | Fix deferred | ||
| Red Hat Enterprise Linux 6 | ghostscript | Fix deferred | ||
| Red Hat Enterprise Linux 7 | ghostscript | Fix deferred | ||
| Red Hat Enterprise Linux 8 | ghostscript | Fix deferred | ||
| Red Hat Enterprise Linux 9 | ghostscript | Fix deferred |
Показывать по
Дополнительная информация
Статус:
4 Medium
CVSS3
Связанные уязвимости
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdev ...
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
Уязвимость функции ocr_begin_page набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
4 Medium
CVSS3