PT-2020-5559 · Artifex+6 · Ghostscript+6

Suhwan

·

Published

2020-08-13

·

Updated

2022-06-29

·

CVE-2020-16306

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GhostScript versions prior to 9.51
Description A null pointer dereference issue in the devices/gdevtsep.c component of GhostScript allows a remote attacker to cause a denial of service via a crafted postscript file.
Recommendations For versions prior to 9.51, update to version 9.51 to resolve the issue. As a temporary workaround, consider restricting the processing of postscript files from untrusted sources until the update is applied.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1852
BDU:2021-01158
CESA-2021_1852
CVE-2020-16306
DLA-2335-1
DSA-4748-1
MGASA-2020-0344
RHSA-2021:1852
RHSA-2021_1852
RLSA-2021:1852
USN-4469-1

Affected Products

Almalinux
Centos
Ghostscript
Linuxmint
Red Hat
Rocky Linux
Ubuntu