PT-2020-14698 · Artifex+3 · Artifex Ghostscript+3

Published

2020-07-28

·

Updated

2024-06-15

·

CVE-2020-15900

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions 9.50 through 9.52
Description A memory corruption issue was found in Artifex Ghostscript, allowing overriding of file access controls through the use of a non-standard PostScript operator. The rsearch calculation for the post size resulted in a size that was too large, and could underflow to max uint32 t. This issue can lead to modification of files and execution of arbitrary commands when opening specially crafted PostScript documents. The vulnerability can be exploited to gain access to files in the file system and execute arbitrary code in the system.
Recommendations For Artifex Ghostscript versions 9.50 through 9.52, update to a version that includes the fix for this issue, as committed in 5d499272b95a6b890a1397e11d20937de000d31b. As a temporary workaround, consider restricting the use of non-standard PostScript operators, such as rsearch, to minimize the risk of exploitation. Avoid opening specially crafted PostScript documents until the issue is resolved.

Fix

Memory Corruption

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15900
OPENSUSE-SU-2020:1142-1
OPENSUSE-SU-2020:1146-1
OPENSUSE-SU-2020_1142-1
OPENSUSE-SU-2020_1146-1
OPENSUSE-SU-2024:10783-1
SUSE-SU-2020:2095-1
SUSE-SU-2020:2097-1
SUSE-SU-2020_2095-1
SUSE-SU-2020_2097-1
USN-4445-1

Affected Products

Artifex Ghostscript
Linuxmint
Suse
Ubuntu