Off-by-One Error in Ghostscript's TrueType Interpreter
CVE-2009-3743

Currently unrated

What is CVE-2009-3743?

An off-by-one error in the Ins_MINDEX function of Ghostscript's TrueType bytecode interpreter creates a risk for remote attackers. By supplying a specially crafted TrueType font within a document, attackers can trigger an integer overflow that leads to heap-based buffer overflow conditions. This vulnerability may allow unauthorized execution of arbitrary code or result in a denial of service through heap memory corruption, exposing systems to significant threats.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.