Hide Forgot
A missing boundary check flaw was found in the Ghostscript's JBIG2 decoding library. An attacker could create a specially-crafted PDF file which could cause Ghostscript to crash, or, potentially execute arbitrary code, when opened by the victim. Acknowledgements: Red Hat would like to thank Alin Rad Pop of Secunia Research for responsibly reporting this flaw.
This issue was reported by Alin Rad Pop, Secunia Research.
Created attachment 337747 [details] Upstream patch from Ralph Giles
Secunia advisory: http://secunia.com/secunia_research/2009-21/
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2009:0421 https://rhn.redhat.com/errata/RHSA-2009-0421.html
ghostscript-8.63-3.fc9 has been submitted as an update for Fedora 9. http://admin.fedoraproject.org/updates/ghostscript-8.63-3.fc9
ghostscript-8.63-6.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
ghostscript-8.63-3.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.