PT-2017-16942 · Artifex · Ghostscript

Kamil Frankowicz

·

Publicado

2017-02-24

·

Atualizado

2017-11-29

·

CVE-2017-6196

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostscript versions prior to ecceafe3abba2714ef9b432035fe0739d9b1a283
Description The issue is related to multiple use-after-free vulnerabilities in the gx image enum begin function. These vulnerabilities can be exploited by remote attackers using a crafted PostScript document, potentially causing a denial of service (application crash) or having other unspecified impacts.
Recommendations For Ghostscript versions prior to ecceafe3abba2714ef9b432035fe0739d9b1a283, update to a version that includes the fix for the use-after-free vulnerabilities in the gx image enum begin function.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6196
MGASA-2017-0430

Produtos afetados

Ghostscript