NULL pointer dereference in Ghostscript - CVE-2017-7207

 

NULL pointer dereference in Ghostscript - CVE-2017-7207

Published: May 25, 2017


Vulnerability identifier: #VU6709
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7207
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error within the mem_get_bits_rectangle() function in base/gdevmem.c in Ghostscript. A remote attacker can create a specially crafted PostScript file, pass it to the affected application and crash it.


Affected software

Ghostscript
Debian Linux
Red Hat Enterprise Linux Server
SUSE Linux
Fedora
ghostscript (Alpine package)
ghostscript

How to mitigate CVE-2017-7207

Update to version 9.21.

ghostscript (Alpine package) - update to 9.21-r0
ghostscript - addressed in versions 9.20-7.fc24, 9.20-7.fc25, 9.20-8.fc26

External References

Related Security Bulletins