Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27792

Опубликовано: 06 нояб. 2019
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ghostscriptOut of support scope
Red Hat Enterprise Linux 7ghostscriptOut of support scope
Red Hat Enterprise Linux 9ghostscriptNot affected
Red Hat Enterprise Linux 8ghostscriptFixedRHSA-2025:436230.04.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2247179ghostscript: heap buffer over write vulnerability in GhostScript's lp8000_print_page() in gdevlp8k.c

EPSS

Процентиль: 14%
0.00045
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 3 лет назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
nvd
около 3 лет назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
debian
около 3 лет назад

A heap-based buffer overwrite vulnerability was found in GhostScript's ...

CVSS3: 7.1
github
около 3 лет назад

A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k.c file. An attacker could trick a user to open a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
fstec
почти 6 лет назад

Уязвимость функции lp8000_print_page() компонента gdevlp8k.c набора программного обеспечения обработки документов Ghostscript, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

EPSS

Процентиль: 14%
0.00045
Низкий

7.1 High

CVSS3