CVE-2016-10219
published 2017-04-03CVE-2016-10219: The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error…
PriorityP418medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.86%
76.9th percentile
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | — | — |
| artifex | ghostscript | >= 0 < 9.20~dfsg-3.1 | 9.20~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.20~dfsg-3.1 | 9.20~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.20~dfsg-3.1 | 9.20~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.20~dfsg-3.1 | 9.20~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.10~dfsg-0ubuntu10.7 | 9.10~dfsg-0ubuntu10.7 |
| artifex | ghostscript | >= 0 < 9.10~dfsg-0ubuntu10.9 | 9.10~dfsg-0ubuntu10.9 |
| artifex | ghostscript | >= 0 < 9.18~dfsg~0-0ubuntu2.4 | 9.18~dfsg~0-0ubuntu2.4 |
| artifex | ghostscript | >= 0 < 9.18~dfsg~0-0ubuntu2.6 | 9.18~dfsg~0-0ubuntu2.6 |
| debian | ghostscript | < ghostscript 9.20~dfsg-3.1 (bookworm) | ghostscript 9.20~dfsg-3.1 (bookworm) |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2gqv-9xv4-43w4: The intersect function in base/gxfill
ghsa_unreviewed·2022-05-17
CVE-2016-10219 [MEDIUM] CWE-369 GHSA-2gqv-9xv4-43w4: The intersect function in base/gxfill
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
OSV
ghostscript regression
osv·2017-05-16·CVSS 5.5
[MEDIUM] ghostscript regression
ghostscript regression
USN-3272-1 fixed vulnerabilities in Ghostscript. This change introduced
a regression when the DELAYBIND feature is used with the eqproc
command. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ghostscript improperly handled parameters to
the rsdparams and eqproc commands. An attacker could use these to
craft a malicious document that could disable -dSAFER protections,
thereby allowing the execution of arbitrary code, or cause a denial
of service (application crash). (CVE-2017-8291)
Kamil Frankowicz discovered a use-after-free vulnerability in the
color management module of Ghostscript. An attacker could use this
to cause a denial of service (application crash). (CVE-2016-10217)
Kamil Frankowic
OSV
ghostscript vulnerabilities
osv·2017-04-28·CVSS 5.5
CVE-2017-8291 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript improperly handled parameters to
the rsdparams and eqproc commands. An attacker could use these to
craft a malicious document that could disable -dSAFER protections,
thereby allowing the execution of arbitrary code, or cause a denial
of service (application crash). (CVE-2017-8291)
Kamil Frankowicz discovered a use-after-free vulnerability in the
color management module of Ghostscript. An attacker could use this
to cause a denial of service (application crash). (CVE-2016-10217)
Kamil Frankowicz discovered a divide-by-zero error in the scan
conversion code in Ghostscript. An attacker could use this to cause
a denial of service (application crash). (CVE-2016-10219)
Kamil Frankowicz discovered multiple NULL pointer dereference
OSV
CVE-2016-10219: The intersect function in base/gxfill
osv·2017-04-03·CVSS 5.5
CVE-2016-10219 [MEDIUM] CVE-2016-10219: The intersect function in base/gxfill
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
Ubuntu
Ghostscript regression
vendor_ubuntu·2017-05-16·CVSS 5.5
[MEDIUM] Ghostscript regression
Title: Ghostscript regression
Summary: USN-3272-1 introduced a regression in Ghostscript.
USN-3272-1 fixed vulnerabilities in Ghostscript. This change introduced
a regression when the DELAYBIND feature is used with the eqproc
command. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ghostscript improperly handled parameters to
the rsdparams and eqproc commands. An attacker could use these to
craft a malicious document that could disable -dSAFER protections,
thereby allowing the execution of arbitrary code, or cause a denial
of service (application crash). (CVE-2017-8291)
Kamil Frankowicz discovered a use-after-free vulnerability in the
color management module of Ghostscript. An attacker could use this
to cause a deni
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2017-04-28·CVSS 5.5
CVE-2016-10217 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript improperly handled parameters to
the rsdparams and eqproc commands. An attacker could use these to
craft a malicious document that could disable -dSAFER protections,
thereby allowing the execution of arbitrary code, or cause a denial
of service (application crash). (CVE-2017-8291)
Kamil Frankowicz discovered a use-after-free vulnerability in the
color management module of Ghostscript. An attacker could use this
to cause a denial of service (application crash). (CVE-2016-10217)
Kamil Frankowicz discovered a divide-by-zero error in the scan
conversion code in Ghostscript. An attacker could use this to cause
a denial of service (application crash). (CVE-2016-10
Red Hat
ghostscript: Divide-by-zero in the intersect function
vendor_redhat·2016-12-23·CVSS 5.5
CVE-2016-10219 [MEDIUM] CWE-369 ghostscript: Divide-by-zero in the intersect function
ghostscript: Divide-by-zero in the intersect function
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
Package: ghostscript (Red Hat Enterprise Linux 5) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 6) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 7) - Will not fix
Package: ghostscript (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2016-10219: ghostscript - The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9....
vendor_debian·2016·CVSS 5.5
CVE-2016-10219 [MEDIUM] CVE-2016-10219: ghostscript - The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9....
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 9.20~dfsg-3.1)
bullseye: resolved (fixed in 9.20~dfsg-3.1)
forky: resolved (fixed in 9.20~dfsg-3.1)
sid: resolved (fixed in 9.20~dfsg-3.1)
trixie: resolved (fixed in 9.20~dfsg-3.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10219 ghostscript: Divide-by-zero in the intersect function
bugzilla·2017-04-12·CVSS 5.5
CVE-2016-10219 [MEDIUM] CVE-2016-10219 ghostscript: Divide-by-zero in the intersect function
CVE-2016-10219 ghostscript: Divide-by-zero in the intersect function
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript allows attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;h=4bef1a1d32e29b68855616020dbff574b9cda08f
Upstream bug:
https://bugs.ghostscript.com/show_bug.cgi?id=697453
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1441581]
Bugzilla
CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
bugzilla·2017-04-12·CVSS 5.5
CVE-2016-10217 [MEDIUM] CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
http://www.debian.org/security/2017/dsa-3838http://www.ghostscript.com/cgi-bin/findgit.cgi?4bef1a1d32e29b68855616020dbff574b9cda08fhttps://bugs.ghostscript.com/show_bug.cgi?id=697453https://security.gentoo.org/glsa/201708-06http://www.debian.org/security/2017/dsa-3838http://www.ghostscript.com/cgi-bin/findgit.cgi?4bef1a1d32e29b68855616020dbff574b9cda08fhttps://bugs.ghostscript.com/show_bug.cgi?id=697453https://security.gentoo.org/glsa/201708-06
2017-04-03
Published