CVE-2008-0411 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 14.5% (pctl 97)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 14.52% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-02-28 |
| Last modified | 2026-06-16 |
Affected (14)
| Vendor | Product |
|---|---|
| debian | debian linux |
| ghostscript | ghostscript |
| mandrakesoft | mandrake linux |
| mandrakesoft | mandrake linux corporate server |
| mandrakesoft | mandrakesoft corporate server |
| redhat | desktop |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux desktop workstation |
| rpath | rpath linux |
| suse | novell linux pos |
| suse | open suse |
| suse | suse linux |
| suse | suse open enterprise server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ghostscript 8.0.1/8.15 - 'zseticcspace()' Remote Buffer Overflow | 2008-02-27 |
References
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00009.html
- http://scary.beasts.org/security/CESA-2008-001.html
- http://secunia.com/advisories/29101
- http://secunia.com/advisories/29103
- http://secunia.com/advisories/29112
- http://secunia.com/advisories/29135
- http://secunia.com/advisories/29147
- http://secunia.com/advisories/29154
- http://secunia.com/advisories/29169
- http://secunia.com/advisories/29196
- http://secunia.com/advisories/29314
- http://secunia.com/advisories/29768
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.370633
- http://wiki.rpath.com/Advisories:rPSA-2008-0082
- http://www.debian.org/security/2008/dsa-1510
- http://www.gentoo.org/security/en/glsa/glsa-200803-14.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:055
- http://www.redhat.com/support/errata/RHSA-2008-0155.html
- http://www.securityfocus.com/archive/1/488932/100/0/threaded
- http://www.securityfocus.com/archive/1/488946/100/0/threaded
→ the Explorer · watch your stack · NVD