Out-of-bounds read in Ghostscript - CVE-2017-11714
Published: September 5, 2017
Vulnerability identifier: #VU8078
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11714
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS conditions on the target system.
The weakness exists due to out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c when handling references to the scanner state structure by psi/ztoken.c. A remote attacker can send a specially crafted PostScript document, trick the victim into processing it, trigger out-of-bounds read and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists due to out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c when handling references to the scanner state structure by psi/ztoken.c. A remote attacker can send a specially crafted PostScript document, trick the victim into processing it, trigger out-of-bounds read and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
Ghostscript
Debian Linux
Ubuntu
Debian Linux
Ubuntu
How to mitigate CVE-2017-11714
Update to the latest version.