PT-2020-5542 · Artifex+7 · Ghostscript+7
Published
2020-08-13
·
Updated
2022-08-24
·
CVE-2020-16299
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Ghostscript version 9.50
Description
The issue is related to a Division by Zero error in the
bj10v print page() function, located in contrib/japanese/gdev10v.c, which can be exploited by a remote attacker to cause a denial of service via a crafted PDF file.Recommendations
For Ghostscript version 9.50, update to version 9.51 to resolve the issue. As a temporary workaround, consider restricting the use of the
bj10v print page() function in contrib/japanese/gdev10v.c until the update is applied.Exploit
Fix
DoS
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Ghostscript
Linuxmint
Red Hat
Rocky Linux
Ubuntu