PT-2017-16942 · Artifex · Ghostscript
Kamil Frankowicz
·
Published
2017-02-24
·
Updated
2017-11-29
·
CVE-2017-6196
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ghostscript versions prior to ecceafe3abba2714ef9b432035fe0739d9b1a283
Description
The issue is related to multiple use-after-free vulnerabilities in the gx image enum begin function. These vulnerabilities can be exploited by remote attackers using a crafted PostScript document, potentially causing a denial of service (application crash) or having other unspecified impacts.
Recommendations
For Ghostscript versions prior to ecceafe3abba2714ef9b432035fe0739d9b1a283, update to a version that includes the fix for the use-after-free vulnerabilities in the gx image enum begin function.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscript