SB2017041916 - Multiple vulnerabilities in Ghostscript
Published: April 19, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2017-8908)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.
2) Integer overflow (CVE-ID: CVE-2017-7948)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via a crafted PostScript document.
Remediation
Install update from vendor's website.