Artifex Ghostscript
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*
A buffer overflow vulnerability has been identified in Artifex Ghostscript versions prior to 10.05.0, specifically within the NPDL device. The issue arises in the Japanese contribution file 'gdevnpdl.c', where an integer overflow during the calculation of width and height can lead to the allocation of a compression buffer that is shorter than required, creating a buffer overflow condition.
Exploitation of this vulnerability leads to a compression buffer overflow, which can commonly result in arbitrary code execution.
The vulnerability can be reproduced by using Ghostscript with the NPDL device. After applying the patch, the exploit can be executed by processing a PostScript file that triggers the buffer overflow via the 'npdl' device.
Users can update to Ghostscript version 10.05.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.