Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7h9w-vh8m-rj5g

Опубликовано: 20 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k.c file. An attacker could trick a user to open a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k.c file. An attacker could trick a user to open a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

EPSS

Процентиль: 9%
0.00036
Низкий

7.1 High

CVSS3

Дефекты

CWE-119
CWE-122
CWE-400

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 3 года назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
redhat
больше 5 лет назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
nvd
почти 3 года назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
debian
почти 3 года назад

A heap-based buffer overwrite vulnerability was found in GhostScript's ...

CVSS3: 7.1
fstec
больше 5 лет назад

Уязвимость функции lp8000_print_page() компонента gdevlp8k.c набора программного обеспечения обработки документов Ghostscript, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

EPSS

Процентиль: 9%
0.00036
Низкий

7.1 High

CVSS3

Дефекты

CWE-119
CWE-122
CWE-400