Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8908

Опубликовано: 12 мая 2017
Источник: debian
EPSS Низкий

Описание

The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ghostscriptfixed9.22~dfsg-1package
ghostscriptnot-affectedjessiepackage
ghostscriptnot-affectedwheezypackage

Примечания

  • https://bugs.ghostscript.com/show_bug.cgi?id=697810

  • edgebuffer scan converter was made default only in: https://git.ghostscript.com/?p=ghostpdl.git;h=dd5da2cb3e08398ac6d86598b36b00994d058308

  • But the vulnerable code via base/gxscan.c, a new scan converter introduced in 9.20 is present.

EPSS

Процентиль: 60%
0.00391
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

CVSS3: 3.3
redhat
почти 9 лет назад

The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

CVSS3: 5.5
nvd
больше 8 лет назад

The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

CVSS3: 5.5
github
больше 3 лет назад

The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

EPSS

Процентиль: 60%
0.00391
Низкий