NULL pointer dereference in Ghostscript - CVE-2017-5951
Published: May 25, 2017
Vulnerability identifier: #VU6708
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5951
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the mem_get_bits_rectangle() function in base/gdevmem.c in Ghostscript. A remote attacker can create a specially crafted file, pass it to the affected application and crash it.
The vulnerability exists due to a NULL pointer dereference error within the mem_get_bits_rectangle() function in base/gdevmem.c in Ghostscript. A remote attacker can create a specially crafted file, pass it to the affected application and crash it.
Affected software
Ghostscript
Debian Linux
SUSE Linux
Fedora
ghostscript (Alpine package)
ghostscript
Debian Linux
SUSE Linux
Fedora
ghostscript (Alpine package)
ghostscript
How to mitigate CVE-2017-5951
Update to version 9.21.
ghostscript (Alpine package) - update to 9.21-r0
ghostscript - addressed in versions 9.20-9.fc24, 9.20-9.fc25, 9.20-10.fc26
ghostscript - addressed in versions 9.20-9.fc24, 9.20-9.fc25, 9.20-10.fc26
External References
Related Security Bulletins
- SUSE Linux update for ghostscript
- Multiple vulnerabilities in Ghostscript
- SUSE Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- Debian update for ghostscript
- NULL pointer dereference in ghostscript (Alpine package)
- Fedora 26 update for ghostscript
- Fedora 25 update for ghostscript
- Fedora 24 update for ghostscript