Out-of-bounds read in Ghostscript - CVE-2017-9739
Published: October 2, 2017
Vulnerability identifier: #VU8645
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9739
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS conditions on the target system.
The weakness exists due to out-of-bounds read in the Ins_JMPR function in base/ttinterp.c when processing documents. A remote attacker can send a specially crafted document, trick the victim into processing it, trigger out-of-bounds read and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists due to out-of-bounds read in the Ins_JMPR function in base/ttinterp.c when processing documents. A remote attacker can send a specially crafted document, trick the victim into processing it, trigger out-of-bounds read and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
Ghostscript
Debian Linux
Ubuntu
Debian Linux
Ubuntu
How to mitigate CVE-2017-9739
Install update from GIT repository.
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=c501a58f8d5650c8ba21d447c0d6f07eafcb0f15
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=c501a58f8d5650c8ba21d447c0d6f07eafcb0f15