PT-2017-16942 · Artifex · Ghostscript

Kamil Frankowicz

·

Published

2017-02-24

·

Updated

2017-11-29

·

CVE-2017-6196

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostscript versions prior to ecceafe3abba2714ef9b432035fe0739d9b1a283
Description The issue is related to multiple use-after-free vulnerabilities in the gx image enum begin function. These vulnerabilities can be exploited by remote attackers using a crafted PostScript document, potentially causing a denial of service (application crash) or having other unspecified impacts.
Recommendations For Ghostscript versions prior to ecceafe3abba2714ef9b432035fe0739d9b1a283, update to a version that includes the fix for the use-after-free vulnerabilities in the gx image enum begin function.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6196
MGASA-2017-0430

Affected Products

Ghostscript