Ghostscript 10.08.0 之前的版本在 JPEG 2000 输出适配器( )中存在一个基于堆的缓冲区溢出漏洞。攻击者可以通过提供一个包含 JPEG 2000 图像的经过精心构造的 PDF 文件,使图像各分量的子采样因子不匹配,从而引发内存破坏。当图像分量声明了不同的子采样值时,非同比例(non-samescale)且子字节深度的输出路径会分配一个按打包输出大小计算的行缓冲区,但无论实际位深度如何,每列输出均写入完整的 1 字节,导致超出分配大小,破坏内部块分配器元数据,进而可能导致代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Artifex Software | Ghostscript | < 10.08.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Artifex Software | Ghostscript | 0 ~ 10.08.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet