Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7978

Опубликовано: 23 мая 2017
Источник: debian

Описание

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ghostscriptfixed9.19~dfsg-3.1package

Примечания

  • Upstream bug: http://bugs.ghostscript.com/show_bug.cgi?id=697179

  • Reproducer: http://bugs.ghostscript.com/show_bug.cgi?id=697179#c0

  • Patch: https://git.ghostscript.com/?p=ghostpdl.git;h=6f749c0c44e7b9e09737b9f29edf29925a34f0cf

  • https://www.openwall.com/lists/oss-security/2016/10/05/7

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

CVSS3: 5.8
redhat
почти 10 лет назад

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

CVSS3: 9.8
nvd
около 9 лет назад

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

CVSS3: 9.8
github
около 4 лет назад

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

suse-cvrf
почти 10 лет назад

Security update for ghostscript-library