---------------------------------------------------------------------- Looking for a job? Secunia is hiring skilled researchers and talented developers. http://secunia.com/company/jobs/ ---------------------------------------------------------------------- TITLE: GhostScript PostScript File Processing Vulnerabilities SECUNIA ADVISORY ID: SA39753 VERIFY ADVISORY: http://secunia.com/advisories/39753/ DESCRIPTION: Dan Rosenberg has reported some vulnerabilities in GhostScript, which can potentially be exploited by malicious people to compromise a user's system. 1) An error in the processing of PostScript files can be exploited to cause a memory corruption via recursive function calls and may allow execution of arbitrary code via a specially crafted PostScript file. 2) An error in the handling of overly long identifiers can be exploited to cause a stack-based buffer overflow via a specially crafted PostScript file. Successful exploitation allows execution of arbitrary code. The vulnerabilities are reported in 8.70. Other versions may also be affected. SOLUTION: Do not process untrusted PostScript files. PROVIDED AND/OR DISCOVERED BY: Dan Rosenberg ORIGINAL ADVISORY: Dan Rosenberg: http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0135.html https://bugs.launchpad.net/ubuntu/+source/ghostscript/+bug/546009 http://bugs.ghostscript.com/show_bug.cgi?id=691295 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------