NULL pointer dereference in Ghostscript - CVE-2016-10220
Published: May 25, 2017
Vulnerability identifier: #VU6707
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10220
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference error within the gs_makewordimagedevice() function in base/gsdevmem.c. A remote attacker can create a specially crafted PDF file, pass it to the affected application, trigger NULL pointer dereference and crash the application.
The vulnerability exists due to NULL pointer dereference error within the gs_makewordimagedevice() function in base/gsdevmem.c. A remote attacker can create a specially crafted PDF file, pass it to the affected application, trigger NULL pointer dereference and crash the application.
Affected software
Ghostscript
Debian Linux
SUSE Linux
Fedora
ghostscript
Debian Linux
SUSE Linux
Fedora
ghostscript
How to mitigate CVE-2016-10220
Update to version 9.21.
ghostscript - addressed in versions 9.20-9.fc24, 9.20-9.fc25, 9.20-10.fc26