cbcvebase.
CVE-2016-7976
published 2017-08-07

CVE-2016-7976: The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

PriorityP261high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
23.45%
97.5th percentile
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

Affected

9 ranges
VendorProductVersion rangeFixed in
artifexghostscript
artifexghostscript
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.10~dfsg-0ubuntu10.59.10~dfsg-0ubuntu10.5
artifexghostscript>= 0 < 9.18~dfsg~0-0ubuntu2.29.18~dfsg~0-0ubuntu2.2
debianghostscript< ghostscript 9.19~dfsg-3.1 (bookworm)ghostscript 9.19~dfsg-3.1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

command%pipe% in paths
path/usr/share/ghostscript/9.20/iccprofiles/../../../../../etc/passwd
urlhttp://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=6d444c273da5
  • Monitor Ghostscript process invocations for use of '%pipe%' strings within userparams or path arguments, which indicates attempted exploitation of this CVE to achieve remote shell execution.
  • Detect path traversal sequences (e.g., '../../../../../') in file open calls originating from Ghostscript's ICC profile handling, particularly under the iccprofiles directory.
  • Flag Ghostscript processes opening sensitive files (e.g., /etc/passwd) directly from the root filesystem, which may indicate exploitation of the directory traversal fallback behavior.
  • Code execution via crafted userparams is only possible in Ghostscript versions 9.18 and above; scope detection efforts on those versions as a priority.
  • The -dSAFER flag does NOT prevent exploitation; do not rely on it as a mitigation indicator when triaging Ghostscript process activity.
  • ·Ghostscript versions prior to 9.18 are NOT vulnerable to code execution via this CVE; they may still be affected by directory traversal but not remote shell.
  • ·Ghostscript versions prior to 9.x (e.g., 8.70) lack ICC profile management entirely and are not affected by this CVE.
  • ·The -dSAFER flag is insufficient to prevent exploitation; path traversal and command execution remain possible even with this flag enabled.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.