Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7h9w-vh8m-rj5g

Опубликовано: 20 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k.c file. An attacker could trick a user to open a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k.c file. An attacker could trick a user to open a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

EPSS

Процентиль: 14%
0.00045
Низкий

7.1 High

CVSS3

Дефекты

CWE-119
CWE-122
CWE-400

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 3 лет назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
redhat
почти 6 лет назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
nvd
около 3 лет назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
debian
около 3 лет назад

A heap-based buffer overwrite vulnerability was found in GhostScript's ...

CVSS3: 7.1
fstec
около 6 лет назад

Уязвимость функции lp8000_print_page() компонента gdevlp8k.c набора программного обеспечения обработки документов Ghostscript, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

EPSS

Процентиль: 14%
0.00045
Низкий

7.1 High

CVSS3

Дефекты

CWE-119
CWE-122
CWE-400