Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
2009-04-16T15:12:57.343
2025-04-09T00:30:58.490
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ghostscript | ghostscript | ≤ 8.64 | Yes |
Application | ghostscript | ghostscript | 0 | Yes |
Application | ghostscript | ghostscript | 5.50 | Yes |
Application | ghostscript | ghostscript | 7.07 | Yes |
Application | ghostscript | ghostscript | 8.0.1 | Yes |
Application | ghostscript | ghostscript | 8.15 | Yes |
Application | ghostscript | ghostscript | 8.15.2 | Yes |
Application | ghostscript | ghostscript | 8.54 | Yes |
Application | ghostscript | ghostscript | 8.56 | Yes |
Application | ghostscript | ghostscript | 8.57 | Yes |
Application | ghostscript | ghostscript | 8.60 | Yes |
Application | ghostscript | ghostscript | 8.61 | Yes |
Application | ghostscript | ghostscript | 8.62 | Yes |
Application | ghostscript | ghostscript | 8.63 | Yes |