ghostscript -- exploitable buffer overflow in (T)BCP in PS interpreter
In Artifex Ghostscript through 10.01.0, there is a buffer overflow
leading to potential corruption of data internal to the PostScript
interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode,
TBCPEncode, and TBCPDecode. If the write buffer is filled to one
byte less than full, and one then tries to write an escaped character,
two bytes are written.
Copyright © 2003-2005 Jacques Vidrine and contributors.
Please see the source of this document for full copyright