Out-of-bounds read in GhostXPS - CVE-2017-9611
Published: September 30, 2017 / Updated: October 2, 2017
GhostXPS
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to boundary error in Ins_MIRP function in base/ttinterp.c. A remote unauthenticated attacker can create a specially crafted document, trigger heap-based out-o-bounds memory read and perform a denial of service (DoS) attack.
How to mitigate CVE-2017-9611
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=c7c55972758a93350882c32147801a3485b010fe