CVE-2007-6725
ghostscript - several vulnerabilities
EPSS 6.2%
Description
The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.
How to fix CVE-2007-6725
To remediate CVE-2007-6725, upgrade the affected package to a fixed version below.
- Debian/ghostscript—upgrade to 8.63.dfsg.1-1 or later
- Debian/ghostscript—upgrade to 8.62.dfsg.1-3.2lenny4 or later
Is CVE-2007-6725 being exploited?
Moderate — EPSS is 6.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 8.63.dfsg.1-1
- from 0, < 8.62.dfsg.1-3.2lenny4