Here is a crash file for the gs command.
The crash can be triggered with the following command on older versions of Ghostscript:
$ ps2pdf test.ps
The affected versions are still shipped by various distributions.
ps2pdf is a shell script that calls the gs binary in the following way:
$ /usr/bin/gs -P- -dSAFER -dCompatibilityLevel=1.4 -q -P- -dNOPAUSE -dBATCH -sDEVICE=pdfwrite -sstdout=%stderr -sOutputFile=test.pdf -P- -dSAFER -dCompatibilityLevel=1.4 -c .setpdfwrite -f test.ps
I attached gdb and valgrind sessions showing the crash on RHEL 6.6 and RHEL 7.1.1503.
The versions of the affected packages on RHEL are:
The problem does not occur with current source revision.
The following commit fixes the segfault, but the problem is not mentioned in
the commit log:
The offending file seems to be gs/Resource/Init/gs_ttf.ps
If one replaces this file with the one from the specified commit (or from
the current master) on RHEL 7.1.1503 or RHEL 6.6, the segfault does not
Since the influence of this commit on the problem is not yet fully understood,
the problem might still be present in current version of gs.
Could you please make this bug private so I can attach the crash file ?
Created attachment 11743 [details]
Created attachment 11744 [details]
Created attachment 11745 [details]
Created attachment 11746 [details]
Created attachment 11747 [details]
The following CVE id was assigned to this issue by RedHat:
Fixed in current version.
*** This bug has been marked as a duplicate of bug 696070 ***