PT-2026-92028 · Unknown+2 · Ghostscript+2
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ghostscript versions prior to 10.08.0
Description
A heap-based buffer overflow exists in the JPEG 2000 output adapter within the
base/sjpx openjpeg.c file. The issue occurs when processing a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. In such cases, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth. This results in memory corruption of internal chunk-allocator metadata, which can lead to a process crash or remote code execution.Recommendations
Update to version 10.08.0.
Exploit
Fix
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscript
Linuxmint
Ubuntu