CVE-2008-0411: Buffer Overflow
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0411?
CVE-2008-0411 has been classified as a critical vulnerability, allowing for remote code execution through specially crafted PostScript files.
How do I fix CVE-2008-0411?
To fix CVE-2008-0411, update Ghostscript to a version later than 8.61, which addresses this buffer overflow issue.
Which software is affected by CVE-2008-0411?
CVE-2008-0411 affects Ghostscript versions 8.61 and earlier, potentially impacting various distributions like Debian and Mandriva.
Can CVE-2008-0411 be exploited remotely?
Yes, CVE-2008-0411 can be exploited remotely by leveraging a malicious PostScript file.
What type of vulnerability is CVE-2008-0411?
CVE-2008-0411 is a stack-based buffer overflow vulnerability.