Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-0411

33
FAUCET Score

CVE-2008-0411 describes a stack-based buffer overflow in the zseticcspace function of Ghostscript 8.61 and earlier, impacting various Linux distributions including Debian, Red Hat, and SUSE. This vulnerability carries a CVSS score of 6.8, indicating a medium severity risk where remote attackers can execute arbitrary code by crafting a malicious PostScript file with a long Range array in a .seticcspace operator. While not listed on the CISA KEV catalog, public exploit code exists, specifically EDB-31309, though there is minimal community discussion or media coverage surrounding this decade-old flaw.

Impacted Technologies

VendorProductVersion(s)CPE
<= 8.61CPE matchmatch criteria
cpe:2.3:a:ghostscript:ghostscript:*:*:*:*:*:*:*:*
0CPE matchmatch criteria
cpe:2.3:a:ghostscript:ghostscript:0:*:*:*:*:*:*:*
8.0.1CPE matchmatch criteria
cpe:2.3:a:ghostscript:ghostscript:8.0.1:*:*:*:*:*:*:*
8.15CPE matchmatch criteria
cpe:2.3:a:ghostscript:ghostscript:8.15:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
14.41%
Probability of exploitation in next 30 days
EPSS Percentile
96.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-31309 · Feb 27, 2008
This CVE's current EPSS score of 0.1441 is in the 96th percentile among its peer group of 19,955 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

debianpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: ghostscript-0:7.05-32.1.13
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: ghostscript-0:7.07-33.2.el4_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: ghostscript-0:8.15.2-9.1.el5_1.1
View patch

Vendor Advisories (1)

redhatCVE-2008-0411Important

ghostscript: stack-based buffer overflow in .seticcspace operator

Feb 27, 2008

References

lists.opensuse.org / opensuse-security-announce/2008-02/msg00009.html
Mailing ListThird Party Advisory
scary.beasts.org / security/CESA-2008-001.html
Exploit
secunia.com / advisories/29101
URL Repurposed
secunia.com / advisories/29103
URL Repurposed
secunia.com / advisories/29112
URL Repurposed
secunia.com / advisories/29135
URL Repurposed
secunia.com / advisories/29147
URL Repurposed
secunia.com / advisories/29154
URL Repurposed
secunia.com / advisories/29169
URL Repurposed
secunia.com / advisories/29196
URL Repurposed
secunia.com / advisories/29314
URL Repurposed
secunia.com / advisories/29768
URL Repurposed
issues.rpath.com / browse/RPL-2217
Broken Link
slackware.com / security/viewer.php
Mailing List
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9557
Broken Link
redhat.com / archives/fedora-package-announce/2008-March/msg00085.html
Release NotesThird Party Advisory
wiki.rpath.com / Advisories:rPSA-2008-0082
Broken Link
debian.org / security/2008/dsa-1510
Patch
gentoo.org / security/en/glsa/glsa-200803-14.xml
Patch
mandriva.com / security/advisories
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0155.html
URL Repurposed
securityfocus.com / archive/1/488932/100/0/threaded
Broken LinkVDB Entry
securityfocus.com / archive/1/488946/100/0/threaded
Broken LinkVDB Entry
securityfocus.com / bid/28017
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
ubuntu.com / usn/usn-599-1
Third Party Advisory
vupen.com / english/advisories/2008/0693/references
Not Applicable