PT-2017-4163 · Artifex+6 · Artifex Ghostscript+6

Published

2017-04-26

·

Updated

2025-12-10

·

CVE-2017-8291

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions through 2017-04-26
Description The issue is related to a type confusion vulnerability in the .rsdparams operator, allowing remote command execution and bypass of the -dSAFER protection mechanism. This can be achieved by using a crafted .eps document with a "/OutputFile (%pipe%" substring as input to the gs program. The vulnerability was exploited in the wild in April 2017. It is also used by the APT37 group to target individuals for intelligence gathering, often through phishing emails containing malicious attachments that exploit an old EPS vulnerability in the Hangul text processor.
Recommendations For Artifex Ghostscript versions through 2017-04-26, update to a version released after 2017-04-26 to fix the vulnerability. As a temporary workaround, consider disabling the use of .rsdparams operator in crafted .eps documents until a patch is available. Restrict access to the gs program to minimize the risk of exploitation. Avoid using the "/OutputFile (%pipe%" substring in .eps documents until the issue is resolved.

Exploit

Fix

Incorrect Type Conversion or Cast

Type Confusion

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2344
BDU:2021-05648
CESA-2017_1230
CVE-2017-8291
DLA-932-1
DSA-3838-1
ELSA-2017-1230
MGASA-2017-0133
OPENSUSE-SU-2017_1203-1
OPENSUSE-SU-2024:10783-1
RHSA-2017:1230
RHSA-2017_1230
SUSE-SU-2017:1138-1
SUSE-SU-2017:1153-1
SUSE-SU-2017:1322-1
SUSE-SU-2017:1404-1
SUSE-SU-2017_1138-1
SUSE-SU-2017_1153-1
SUSE-SU-2017_1322-1
SUSE-SU-2017_1404-1
USN-3272-1
USN-3272-2

Affected Products

Alt Linux
Artifex Ghostscript
Centos
Hangul
Red Hat
Suse
Ubuntu