Off-by-One Error in Ghostscript's TrueType Interpreter
CVE-2009-3743
Currently unrated
Key Information:
- Vendor
Artifex
- Vendor
- CVE Published:
- 26 August 2010
What is CVE-2009-3743?
An off-by-one error in the Ins_MINDEX function of Ghostscript's TrueType bytecode interpreter creates a risk for remote attackers. By supplying a specially crafted TrueType font within a document, attackers can trigger an integer overflow that leads to heap-based buffer overflow conditions. This vulnerability may allow unauthorized execution of arbitrary code or result in a denial of service through heap memory corruption, exposing systems to significant threats.