VDB
CVE-2009-4270
CVE-2009-4270
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
EPSS 8.64% · 92.6th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
8.64%
92.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| ghostscript | ghostscript | 8.70, 8.64 |
Timeline
- Dec 21, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- GLSA-201412-17 vendor-advisory
- [oss-security] 20091218 Re: possible vulnerability in ghostscript >= 8.64 mailing-list
- MDVSA-2010:134 vendor-advisory
- [oss-security] 20091217 possible vulnerability in ghostscript >= 8.64 mailing-list
- USN-961-1 vendor-advisory
- MDVSA-2010:135 vendor-advisory
- ADV-2009-3597 vdb
- 61140 vdb
- 40580 third-party-advisory
- SUSE-SR:2010:014 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=540760 url
- 37851 third-party-advisory
- 37410 vdb
- http://bugs.ghostscript.com/show_bug.cgi?id=690829 url
- https://nvd.nist.gov/vuln/detail/CVE-2009-4270 advisory