CVE-2009-4897
ghostscript - several vulnerabilities
EPSS 8.3%
Description
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
How to fix CVE-2009-4897
To remediate CVE-2009-4897, upgrade the affected package to a fixed version below.
- Debian/ghostscript—upgrade to 8.70~dfsg-1 or later
- Debian/ghostscript—upgrade to 8.62.dfsg.1-3.2lenny5 or later
Is CVE-2009-4897 being exploited?
Moderate — EPSS is 8.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 8.70~dfsg-1
- from 0, < 8.62.dfsg.1-3.2lenny5