在 Artifex Ghostscript 10.09.0 及更早版本中发现了一个漏洞。该漏洞位于 Pdfwrite 组件的文件 中的函数 。通过操纵输入,可触发基于栈的缓冲区溢出漏洞。该攻击可被远程利用,且已有公开的利用代码(exploit)存在,可能被恶意使用。建议安装补丁以修复此问题。官方已实施解决方案:“我选择采用略有不同的修复方式,即在字体解析循环中使用已定义的宏,而不是在 callsubr 函数中直接使用,因为这种方式更符合‘常规’使用模式。”
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Artifex | Ghostscript | 10.09 |
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet