CVE-2016-10317
published 2017-04-03CVE-2016-10317: The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service…
PriorityP335high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.28%
81.2th percentile
The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | — | — |
| artifex | ghostscript | >= 0 < 9.22~dfsg-2.1 | 9.22~dfsg-2.1 |
| artifex | ghostscript | >= 0 < 9.22~dfsg-2.1 | 9.22~dfsg-2.1 |
| artifex | ghostscript | >= 0 < 9.22~dfsg-2.1 | 9.22~dfsg-2.1 |
| artifex | ghostscript | >= 0 < 9.22~dfsg-2.1 | 9.22~dfsg-2.1 |
| artifex | ghostscript | >= 0 < 9.10~dfsg-0ubuntu10.12 | 9.10~dfsg-0ubuntu10.12 |
| artifex | ghostscript | >= 0 < 9.18~dfsg~0-0ubuntu2.8 | 9.18~dfsg~0-0ubuntu2.8 |
| artifex | ghostscript | >= 0 < 9.22~dfsg+1-0ubuntu1.1 | 9.22~dfsg+1-0ubuntu1.1 |
| debian | ghostscript | < ghostscript 9.22~dfsg-2.1 (bookworm) | ghostscript 9.22~dfsg-2.1 (bookworm) |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwwf-pc5c-f9gm: The fill_threshhold_buffer function in base/gxht_thresh
ghsa_unreviewed·2022-05-14
CVE-2016-10317 [HIGH] CWE-119 GHSA-vwwf-pc5c-f9gm: The fill_threshhold_buffer function in base/gxht_thresh
The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.
OSV
ghostscript vulnerabilities
osv·2018-04-30·CVSS 7.8
CVE-2016-10317 [HIGH] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled certain PostScript
files. An attacker could possibly use this to cause a denial of server.
(CVE-2016-10317)
It was discovered that Ghostscript incorrectly handled certain PDF files.
An attacker could possibly use this to cause a denial of service.
(CVE-2018-10194)
OSV
CVE-2016-10317: The fill_threshhold_buffer function in base/gxht_thresh
osv·2017-04-03·CVSS 7.8
CVE-2016-10317 [HIGH] CVE-2016-10317: The fill_threshhold_buffer function in base/gxht_thresh
The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2018-04-30·CVSS 7.8
CVE-2016-10317 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled certain PostScript
files. An attacker could possibly use this to cause a denial of server.
(CVE-2016-10317)
It was discovered that Ghostscript incorrectly handled certain PDF files.
An attacker could possibly use this to cause a denial of service.
(CVE-2018-10194)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: Heap-buffer overflow in the fill_threshold_buffer function
vendor_redhat·2016-12-31·CVSS 7.8
CVE-2016-10317 [HIGH] CWE-122 ghostscript: Heap-buffer overflow in the fill_threshold_buffer function
ghostscript: Heap-buffer overflow in the fill_threshold_buffer function
The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.
Package: ghostscript (Red Hat Enterprise Linux 5) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 6) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 7) - Will not fix
Package: ghostscript (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2016-10317: ghostscript - The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, I...
vendor_debian·2016·CVSS 7.8
CVE-2016-10317 [HIGH] CVE-2016-10317: ghostscript - The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, I...
The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-2.1)
bullseye: resolved (fixed in 9.22~dfsg-2.1)
forky: resolved (fixed in 9.22~dfsg-2.1)
sid: resolved (fixed in 9.22~dfsg-2.1)
trixie: resolved (fixed in 9.22~dfsg-2.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10317 ghostscript: Heap-buffer overflow in the fill_threshold_buffer function
bugzilla·2017-04-12·CVSS 7.8
CVE-2016-10317 [HIGH] CVE-2016-10317 ghostscript: Heap-buffer overflow in the fill_threshold_buffer function
CVE-2016-10317 ghostscript: Heap-buffer overflow in the fill_threshold_buffer function
The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.
Upstream bug:
https://bugs.ghostscript.com/show_bug.cgi?id=697459
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1441581]
---
NOTE: We're still waiting on upstream to provide a patch for this CVE.
---
Upstream fix :
- Fix bug 697459 Buffer overflow in fill_threshold_buffer
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=362ec9daadb9992b0def3520cd1dc6fa52edd1c4
Bugzilla
CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
bugzilla·2017-04-12·CVSS 5.5
CVE-2016-10217 [MEDIUM] CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
2017-04-03
Published