Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7207

Опубликовано: 19 мар. 2017
Источник: redhat
CVSS3: 3.3

Описание

The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.

A NULL pointer dereference flaw was found in ghostscript's mem_get_bits_rectangle function. A specially crafted postscript document could cause a crash in the context of the gs process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ghostscriptWill not fix
Red Hat Enterprise Linux 6ghostscriptWill not fix
Red Hat OpenShift Enterprise 2ghostscriptWill not fix
Red Hat Enterprise Linux 7ghostscriptFixedRHSA-2017:218001.08.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1434353ghostscript: NULL pointer dereference in mem_get_bits_rectangle()

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.

CVSS3: 5.5
nvd
почти 9 лет назад

The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.

CVSS3: 5.5
debian
почти 9 лет назад

The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscr ...

CVSS3: 5.5
github
больше 3 лет назад

The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.

oracle-oval
больше 8 лет назад

ELSA-2017-2180: ghostscript security and bug fix update (LOW)

3.3 Low

CVSS3