Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27792

Опубликовано: 06 нояб. 2019
Источник: redhat
CVSS3: 7.1

Описание

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ghostscriptOut of support scope
Red Hat Enterprise Linux 7ghostscriptOut of support scope
Red Hat Enterprise Linux 9ghostscriptNot affected
Red Hat Enterprise Linux 8ghostscriptFixedRHSA-2025:436230.04.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2247179ghostscript: heap buffer over write vulnerability in GhostScript's lp8000_print_page() in gdevlp8k.c

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 3 года назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
nvd
почти 3 года назад

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
debian
почти 3 года назад

A heap-based buffer overwrite vulnerability was found in GhostScript's ...

CVSS3: 7.1
github
почти 3 года назад

A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k.c file. An attacker could trick a user to open a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVSS3: 7.1
fstec
больше 5 лет назад

Уязвимость функции lp8000_print_page() компонента gdevlp8k.c набора программного обеспечения обработки документов Ghostscript, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

7.1 High

CVSS3