Bug 493442 (CVE-2007-6725)
Summary: | CVE-2007-6725 ghostscript: DoS (crash) in CCITTFax decoding filter | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | unspecified | CC: | bressers, twaugh | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2010-07-13 14:26:13 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 229174, 450715, 491854, 491855, 491856, 491857, 491858, 492346, 492348 | ||||||
Bug Blocks: | |||||||
Attachments: |
|
Description
Jan Lieskovsky
2009-04-01 18:58:58 UTC
Created attachment 337622 [details]
PoC proving presence of the flaw
This issue affects all versions of the ghostscript package, as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5. Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6725 to the following vulnerability: The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function. This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2009:0421 https://rhn.redhat.com/errata/RHSA-2009-0421.html |