Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10317

Опубликовано: 03 апр. 2017
Источник: debian

Описание

The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ghostscriptfixed9.22~dfsg-2.1package
ghostscriptfixed9.20~dfsg-3.2+deb9u2stretchpackage
ghostscriptfixed9.06~dfsg-2+deb8u7jessiepackage
ghostscriptno-dsawheezypackage

Примечания

  • https://bugs.ghostscript.com/show_bug.cgi?id=697459

  • https://git.ghostscript.com/?p=ghostpdl.git;h=362ec9daadb9992b0def3520cd1dc6fa52edd1c4

  • I got the reproducer file from the bug submitter and tried to reproduce it.

  • Results are the following: sid/stretch with 9.20~dfsg-3 are

  • affected, it even segfaults. But with wheezy 9.05~dfsg-6.3+deb7u2

  • and jessie 9.06~dfsg-2+deb8u4, we have no segfault and valgrind

  • reports no buffer overrun. -- Raphael Hertzog

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVSS3: 5.3
redhat
около 9 лет назад

The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVSS3: 7.8
nvd
почти 9 лет назад

The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVSS3: 7.8
github
больше 3 лет назад

The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVSS3: 5.6
fstec
почти 9 лет назад

Уязвимость функции fill_threshhold_buffer (base/gxht_thresh.c) набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании