Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 618682 (CVE-2017-8908) - app-text/ghostscript-gpl: Out-of-bounds read in mark_line_tr function (CVE-2017-8908)
Summary: app-text/ghostscript-gpl: Out-of-bounds read in mark_line_tr function (CVE-20...
Status: RESOLVED INVALID
Alias: CVE-2017-8908
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: [cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-16 17:34 UTC by Volkan
Modified: 2017-07-17 22:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Volkan 2017-05-16 17:34:18 UTC
The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

Upstream bug:

https://bugs.ghostscript.com/show_bug.cgi?id=697810
Comment 1 Andreas K. Hüttel archtester gentoo-dev 2017-06-08 21:11:53 UTC
(In reply to Volkan from comment #0)
> The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows
> remote attackers to cause a denial of service (out-of-bounds read) via a
> crafted PostScript document.

Nope. Wrong. Does not affect 9.21, but just a range of git master commits.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2017-07-17 22:46:19 UTC
The CVE is wrong.

ghostscript-gpl-9.21 was released March 16th 2017

See http://git.ghostscript.com/?p=ghostpdl.git;a=shortlog;h=refs/tags/ghostscript-9.21

https://bugs.ghostscript.com/show_bug.cgi?id=697810 was reported April 29th 2017 against a bunch of random master commits (as Andreas mentioned).

So this definitely was not in 9.21.

Furthermore, the commits were fixed and reported testing good against the PoC given on upstream bug tracker.

Given this, the vulnerable code never made it to a release or Gentoo (no -9999 in Gentoo either).

CVE assigned for historical purposes.