Out-of-bounds write in Ghostscript - CVE-2020-16304
Published: August 13, 2020 / Updated: August 26, 2020
Vulnerability identifier: #VU45846
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16304
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.50 allows a remote attacker to execute arbitrary code on the system via a crafted eps file.
Affected software
Ghostscript
Gentoo Linux
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
ghostscript (Debian package)
ghostscript (Alpine package)
ghostscript (Ubuntu package)
libgs9 (Ubuntu package)
ghostscript (Red Hat package)
Gentoo Linux
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
ghostscript (Debian package)
ghostscript (Alpine package)
ghostscript (Ubuntu package)
libgs9 (Ubuntu package)
ghostscript (Red Hat package)
How to mitigate CVE-2020-16304
Install update from vendor's website.
Ghostscript - update to 9.51
ghostscript (Debian package) - update to 9.27~dfsg-2+deb10u4
ghostscript (Alpine package) - update to 9.53.1-r0
ghostscript (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.13, 9.26~dfsg+0-0ubuntu0.18.04.13, 9.50~dfsg-5ubuntu4.2
libgs9 (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.13, 9.26~dfsg+0-0ubuntu0.18.04.13, 9.50~dfsg-5ubuntu4.2
ghostscript (Red Hat package) - update to 9.27-1.el8
ghostscript (Debian package) - update to 9.27~dfsg-2+deb10u4
ghostscript (Alpine package) - update to 9.53.1-r0
ghostscript (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.13, 9.26~dfsg+0-0ubuntu0.18.04.13, 9.50~dfsg-5ubuntu4.2
libgs9 (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.13, 9.26~dfsg+0-0ubuntu0.18.04.13, 9.50~dfsg-5ubuntu4.2
ghostscript (Red Hat package) - update to 9.27-1.el8