Vulnerability Intelligence Report
CVE-2008-0411
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
No Active Exploit Signals
CVSS Base Score
6.8
MEDIUM
EPSS Probability:14.41%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| debian | debian_linux | 3.1, 4.0 |
| mandrakesoft | mandrake_linux | 2007, 2007.0_x86_64, 2007.1, 2008.0 |
| mandrakesoft | mandrake_linux_corporate_server | 3.0, 4.0 |
| mandrakesoft | mandrakesoft_corporate_server | 3.0_x86_64, 4.0_x86_64 |
| redhat | desktop | 3.0, 4.0 |
| redhat | enterprise_linux | 5, as_3, as_4, es_3, es_4, ws_3, ws_4 |
| redhat | enterprise_linux_desktop | 5 |
| redhat | enterprise_linux_desktop_workstation | 5 |
| rpath | rpath_linux | 1 |
| suse | novell_linux_pos | 9 |
| suse | open_suse | 10.2, 10.3 |
| suse | suse_linux | 9.0, 10, 10.1 |
| suse | suse_open_enterprise_server | 0 |
| ghostscript | ghostscript | 0, 8.0.1, 8.15 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
14.409%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2008-01-23T00:00:00 |
| Published | 2008-02-28T21:00:00 |
| Patch Date | 2008-02-27 |
| Last Updated | 2024-08-07T07:46:54 |
Community Chatter & Buzz