Vulnerability Details CVE-2009-3743
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.067
EPSS Ranking 90.7%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2009-3743
-
cpe:2.3:a:artifex:afpl_ghostscript:6.0
-
cpe:2.3:a:artifex:afpl_ghostscript:6.01
-
cpe:2.3:a:artifex:afpl_ghostscript:6.50
-
cpe:2.3:a:artifex:afpl_ghostscript:7.00
-
cpe:2.3:a:artifex:afpl_ghostscript:7.03
-
cpe:2.3:a:artifex:afpl_ghostscript:7.04
-
cpe:2.3:a:artifex:afpl_ghostscript:8.00
-
cpe:2.3:a:artifex:afpl_ghostscript:8.11
-
cpe:2.3:a:artifex:afpl_ghostscript:8.12
-
cpe:2.3:a:artifex:afpl_ghostscript:8.13
-
cpe:2.3:a:artifex:afpl_ghostscript:8.14
-
cpe:2.3:a:artifex:afpl_ghostscript:8.50
-
cpe:2.3:a:artifex:afpl_ghostscript:8.51
-
cpe:2.3:a:artifex:afpl_ghostscript:8.52
-
cpe:2.3:a:artifex:afpl_ghostscript:8.53
-
cpe:2.3:a:artifex:afpl_ghostscript:8.54
-
cpe:2.3:a:artifex:ghostscript_fonts:6.0
-
cpe:2.3:a:artifex:ghostscript_fonts:8.11
-
cpe:2.3:a:artifex:gpl_ghostscript:-
-
cpe:2.3:a:artifex:gpl_ghostscript:2
-
cpe:2.3:a:artifex:gpl_ghostscript:2.1
-
cpe:2.3:a:artifex:gpl_ghostscript:2.1.1
-
cpe:2.3:a:artifex:gpl_ghostscript:2.2
-
cpe:2.3:a:artifex:gpl_ghostscript:2.3
-
cpe:2.3:a:artifex:gpl_ghostscript:2.4
-
cpe:2.3:a:artifex:gpl_ghostscript:2.4.1
-
cpe:2.3:a:artifex:gpl_ghostscript:2.4.2
-
cpe:2.3:a:artifex:gpl_ghostscript:2.5
-
cpe:2.3:a:artifex:gpl_ghostscript:2.5.1
-
cpe:2.3:a:artifex:gpl_ghostscript:2.5.2
-
cpe:2.3:a:artifex:gpl_ghostscript:2.6
-
cpe:2.3:a:artifex:gpl_ghostscript:2.6.1
-
cpe:2.3:a:artifex:gpl_ghostscript:2.7
-
cpe:2.3:a:artifex:gpl_ghostscript:2.7.1
-
cpe:2.3:a:artifex:gpl_ghostscript:2.7.2
-
cpe:2.3:a:artifex:gpl_ghostscript:2.8
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.1
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.10
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.2
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.3
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.4
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.5
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.6
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.7
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.8
-
cpe:2.3:a:artifex:gpl_ghostscript:2.9.9
-
cpe:2.3:a:artifex:gpl_ghostscript:3
-
cpe:2.3:a:artifex:gpl_ghostscript:3.0.3
-
cpe:2.3:a:artifex:gpl_ghostscript:3.01
-
cpe:2.3:a:artifex:gpl_ghostscript:3.02
-
cpe:2.3:a:artifex:gpl_ghostscript:3.1
-
cpe:2.3:a:artifex:gpl_ghostscript:3.1.1
-
cpe:2.3:a:artifex:gpl_ghostscript:3.12
-
cpe:2.3:a:artifex:gpl_ghostscript:3.13
-
cpe:2.3:a:artifex:gpl_ghostscript:3.2
-
cpe:2.3:a:artifex:gpl_ghostscript:3.21
-
cpe:2.3:a:artifex:gpl_ghostscript:3.22
-
cpe:2.3:a:artifex:gpl_ghostscript:3.23
-
cpe:2.3:a:artifex:gpl_ghostscript:3.24
-
cpe:2.3:a:artifex:gpl_ghostscript:3.25
-
cpe:2.3:a:artifex:gpl_ghostscript:3.26
-
cpe:2.3:a:artifex:gpl_ghostscript:3.27
-
cpe:2.3:a:artifex:gpl_ghostscript:3.28
-
cpe:2.3:a:artifex:gpl_ghostscript:3.29
-
cpe:2.3:a:artifex:gpl_ghostscript:3.3
-
cpe:2.3:a:artifex:gpl_ghostscript:3.31
-
cpe:2.3:a:artifex:gpl_ghostscript:3.32
-
cpe:2.3:a:artifex:gpl_ghostscript:3.33
-
cpe:2.3:a:artifex:gpl_ghostscript:3.34
-
cpe:2.3:a:artifex:gpl_ghostscript:3.35
-
cpe:2.3:a:artifex:gpl_ghostscript:3.36
-
cpe:2.3:a:artifex:gpl_ghostscript:3.37
-
cpe:2.3:a:artifex:gpl_ghostscript:3.38
-
cpe:2.3:a:artifex:gpl_ghostscript:3.39
-
cpe:2.3:a:artifex:gpl_ghostscript:3.4
-
cpe:2.3:a:artifex:gpl_ghostscript:3.41
-
cpe:2.3:a:artifex:gpl_ghostscript:3.42
-
cpe:2.3:a:artifex:gpl_ghostscript:3.43
-
cpe:2.3:a:artifex:gpl_ghostscript:3.44
-
cpe:2.3:a:artifex:gpl_ghostscript:3.45
-
cpe:2.3:a:artifex:gpl_ghostscript:3.46
-
cpe:2.3:a:artifex:gpl_ghostscript:3.47
-
cpe:2.3:a:artifex:gpl_ghostscript:3.48
-
cpe:2.3:a:artifex:gpl_ghostscript:3.49
-
cpe:2.3:a:artifex:gpl_ghostscript:3.5
-
cpe:2.3:a:artifex:gpl_ghostscript:3.51
-
cpe:2.3:a:artifex:gpl_ghostscript:3.52
-
cpe:2.3:a:artifex:gpl_ghostscript:3.53
-
cpe:2.3:a:artifex:gpl_ghostscript:3.6
-
cpe:2.3:a:artifex:gpl_ghostscript:3.61
-
cpe:2.3:a:artifex:gpl_ghostscript:3.62
-
cpe:2.3:a:artifex:gpl_ghostscript:3.63
-
cpe:2.3:a:artifex:gpl_ghostscript:3.64
-
cpe:2.3:a:artifex:gpl_ghostscript:3.65
-
cpe:2.3:a:artifex:gpl_ghostscript:3.66
-
cpe:2.3:a:artifex:gpl_ghostscript:3.67
-
cpe:2.3:a:artifex:gpl_ghostscript:3.68
-
cpe:2.3:a:artifex:gpl_ghostscript:3.69
-
cpe:2.3:a:artifex:gpl_ghostscript:3.7
-
cpe:2.3:a:artifex:gpl_ghostscript:4
-
cpe:2.3:a:artifex:gpl_ghostscript:4.01
-
cpe:2.3:a:artifex:gpl_ghostscript:4.02
-
cpe:2.3:a:artifex:gpl_ghostscript:4.03
-
cpe:2.3:a:artifex:gpl_ghostscript:4.1
-
cpe:2.3:a:artifex:gpl_ghostscript:4.2
-
cpe:2.3:a:artifex:gpl_ghostscript:4.21
-
cpe:2.3:a:artifex:gpl_ghostscript:4.3
-
cpe:2.3:a:artifex:gpl_ghostscript:4.31
-
cpe:2.3:a:artifex:gpl_ghostscript:4.32
-
cpe:2.3:a:artifex:gpl_ghostscript:4.33
-
cpe:2.3:a:artifex:gpl_ghostscript:4.34
-
cpe:2.3:a:artifex:gpl_ghostscript:4.35
-
cpe:2.3:a:artifex:gpl_ghostscript:4.36
-
cpe:2.3:a:artifex:gpl_ghostscript:4.37
-
cpe:2.3:a:artifex:gpl_ghostscript:4.38
-
cpe:2.3:a:artifex:gpl_ghostscript:4.39
-
cpe:2.3:a:artifex:gpl_ghostscript:4.4
-
cpe:2.3:a:artifex:gpl_ghostscript:4.41
-
cpe:2.3:a:artifex:gpl_ghostscript:4.5
-
cpe:2.3:a:artifex:gpl_ghostscript:4.51
-
cpe:2.3:a:artifex:gpl_ghostscript:4.6
-
cpe:2.3:a:artifex:gpl_ghostscript:4.61
-
cpe:2.3:a:artifex:gpl_ghostscript:4.7
-
cpe:2.3:a:artifex:gpl_ghostscript:4.71
-
cpe:2.3:a:artifex:gpl_ghostscript:4.72
-
cpe:2.3:a:artifex:gpl_ghostscript:4.73
-
cpe:2.3:a:artifex:gpl_ghostscript:4.74
-
cpe:2.3:a:artifex:gpl_ghostscript:4.8
-
cpe:2.3:a:artifex:gpl_ghostscript:4.81
-
cpe:2.3:a:artifex:gpl_ghostscript:5
-
cpe:2.3:a:artifex:gpl_ghostscript:5.01
-
cpe:2.3:a:artifex:gpl_ghostscript:5.02
-
cpe:2.3:a:artifex:gpl_ghostscript:5.03
-
cpe:2.3:a:artifex:gpl_ghostscript:5.04
-
cpe:2.3:a:artifex:gpl_ghostscript:5.05
-
cpe:2.3:a:artifex:gpl_ghostscript:5.06
-
cpe:2.3:a:artifex:gpl_ghostscript:5.07
-
cpe:2.3:a:artifex:gpl_ghostscript:5.1
-
cpe:2.3:a:artifex:gpl_ghostscript:5.2
-
cpe:2.3:a:artifex:gpl_ghostscript:5.21
-
cpe:2.3:a:artifex:gpl_ghostscript:5.22
-
cpe:2.3:a:artifex:gpl_ghostscript:5.23
-
cpe:2.3:a:artifex:gpl_ghostscript:5.24
-
cpe:2.3:a:artifex:gpl_ghostscript:5.25
-
cpe:2.3:a:artifex:gpl_ghostscript:5.26
-
cpe:2.3:a:artifex:gpl_ghostscript:5.27
-
cpe:2.3:a:artifex:gpl_ghostscript:5.28
-
cpe:2.3:a:artifex:gpl_ghostscript:5.3
-
cpe:2.3:a:artifex:gpl_ghostscript:5.31
-
cpe:2.3:a:artifex:gpl_ghostscript:5.32
-
cpe:2.3:a:artifex:gpl_ghostscript:5.33
-
cpe:2.3:a:artifex:gpl_ghostscript:5.34
-
cpe:2.3:a:artifex:gpl_ghostscript:5.35
-
cpe:2.3:a:artifex:gpl_ghostscript:5.36
-
cpe:2.3:a:artifex:gpl_ghostscript:5.37
-
cpe:2.3:a:artifex:gpl_ghostscript:5.38
-
cpe:2.3:a:artifex:gpl_ghostscript:5.39
-
cpe:2.3:a:artifex:gpl_ghostscript:5.4
-
cpe:2.3:a:artifex:gpl_ghostscript:5.5
-
cpe:2.3:a:artifex:gpl_ghostscript:5.6
-
cpe:2.3:a:artifex:gpl_ghostscript:5.61
-
cpe:2.3:a:artifex:gpl_ghostscript:5.62
-
cpe:2.3:a:artifex:gpl_ghostscript:5.63
-
cpe:2.3:a:artifex:gpl_ghostscript:5.64
-
cpe:2.3:a:artifex:gpl_ghostscript:5.65
-
cpe:2.3:a:artifex:gpl_ghostscript:5.66
-
cpe:2.3:a:artifex:gpl_ghostscript:5.67
-
cpe:2.3:a:artifex:gpl_ghostscript:5.68
-
cpe:2.3:a:artifex:gpl_ghostscript:5.69
-
cpe:2.3:a:artifex:gpl_ghostscript:5.7
-
cpe:2.3:a:artifex:gpl_ghostscript:5.71
-
cpe:2.3:a:artifex:gpl_ghostscript:5.72
-
cpe:2.3:a:artifex:gpl_ghostscript:5.73
-
cpe:2.3:a:artifex:gpl_ghostscript:5.8
-
cpe:2.3:a:artifex:gpl_ghostscript:5.81
-
cpe:2.3:a:artifex:gpl_ghostscript:5.82
-
cpe:2.3:a:artifex:gpl_ghostscript:5.83
-
cpe:2.3:a:artifex:gpl_ghostscript:5.84
-
cpe:2.3:a:artifex:gpl_ghostscript:5.85
-
cpe:2.3:a:artifex:gpl_ghostscript:5.86
-
cpe:2.3:a:artifex:gpl_ghostscript:5.87
-
cpe:2.3:a:artifex:gpl_ghostscript:5.88
-
cpe:2.3:a:artifex:gpl_ghostscript:5.89
-
cpe:2.3:a:artifex:gpl_ghostscript:5.9
-
cpe:2.3:a:artifex:gpl_ghostscript:5.91
-
cpe:2.3:a:artifex:gpl_ghostscript:5.92
-
cpe:2.3:a:artifex:gpl_ghostscript:5.93
-
cpe:2.3:a:artifex:gpl_ghostscript:5.94
-
cpe:2.3:a:artifex:gpl_ghostscript:5.95
-
cpe:2.3:a:artifex:gpl_ghostscript:5.96
-
cpe:2.3:a:artifex:gpl_ghostscript:5.97
-
cpe:2.3:a:artifex:gpl_ghostscript:5.98
-
cpe:2.3:a:artifex:gpl_ghostscript:5.99
-
cpe:2.3:a:artifex:gpl_ghostscript:7
-
cpe:2.3:a:artifex:gpl_ghostscript:7.02
-
cpe:2.3:a:artifex:gpl_ghostscript:7.03
-
cpe:2.3:a:artifex:gpl_ghostscript:7.2
-
cpe:2.3:a:artifex:gpl_ghostscript:7.21
-
cpe:2.3:a:artifex:gpl_ghostscript:7.22
-
cpe:2.3:a:artifex:gpl_ghostscript:7.3
-
cpe:2.3:a:artifex:gpl_ghostscript:7.31
-
cpe:2.3:a:artifex:gpl_ghostscript:7.32
-
cpe:2.3:a:artifex:gpl_ghostscript:7.33
-
cpe:2.3:a:artifex:gpl_ghostscript:8
-
cpe:2.3:a:artifex:gpl_ghostscript:8.01
-
cpe:2.3:a:artifex:gpl_ghostscript:8.1
-
cpe:2.3:a:artifex:gpl_ghostscript:8.11
-
cpe:2.3:a:artifex:gpl_ghostscript:8.12
-
cpe:2.3:a:artifex:gpl_ghostscript:8.15
-
cpe:2.3:a:artifex:gpl_ghostscript:8.3
-
cpe:2.3:a:artifex:gpl_ghostscript:8.31
-
cpe:2.3:a:artifex:gpl_ghostscript:8.32
-
cpe:2.3:a:artifex:gpl_ghostscript:8.33
-
cpe:2.3:a:artifex:gpl_ghostscript:8.5
-
cpe:2.3:a:artifex:gpl_ghostscript:8.50
-
cpe:2.3:a:artifex:gpl_ghostscript:8.51
-
cpe:2.3:a:artifex:gpl_ghostscript:8.52
-
cpe:2.3:a:artifex:gpl_ghostscript:8.53
-
cpe:2.3:a:artifex:gpl_ghostscript:8.54
-
cpe:2.3:a:artifex:gpl_ghostscript:8.56
-
cpe:2.3:a:artifex:gpl_ghostscript:8.57
-
cpe:2.3:a:artifex:gpl_ghostscript:8.6
-
cpe:2.3:a:artifex:gpl_ghostscript:8.60
-
cpe:2.3:a:artifex:gpl_ghostscript:8.61
-
cpe:2.3:a:artifex:gpl_ghostscript:8.62
-
cpe:2.3:a:artifex:gpl_ghostscript:8.63
-
cpe:2.3:a:artifex:gpl_ghostscript:8.64
-
cpe:2.3:a:artifex:gpl_ghostscript:8.7
-
cpe:2.3:a:artifex:gpl_ghostscript:8.70