CVE-2016-7976
published 2017-08-07CVE-2016-7976: The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
PriorityP261high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
23.45%
97.5th percentile
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | >= 0 < 9.19~dfsg-3.1 | 9.19~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.19~dfsg-3.1 | 9.19~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.19~dfsg-3.1 | 9.19~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.19~dfsg-3.1 | 9.19~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.10~dfsg-0ubuntu10.5 | 9.10~dfsg-0ubuntu10.5 |
| artifex | ghostscript | >= 0 < 9.18~dfsg~0-0ubuntu2.2 | 9.18~dfsg~0-0ubuntu2.2 |
| debian | ghostscript | < ghostscript 9.19~dfsg-3.1 (bookworm) | ghostscript 9.19~dfsg-3.1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor Ghostscript process invocations for use of '%pipe%' strings within userparams or path arguments, which indicates attempted exploitation of this CVE to achieve remote shell execution. ↗
- →Detect path traversal sequences (e.g., '../../../../../') in file open calls originating from Ghostscript's ICC profile handling, particularly under the iccprofiles directory. ↗
- →Flag Ghostscript processes opening sensitive files (e.g., /etc/passwd) directly from the root filesystem, which may indicate exploitation of the directory traversal fallback behavior. ↗
- →Code execution via crafted userparams is only possible in Ghostscript versions 9.18 and above; scope detection efforts on those versions as a priority. ↗
- →The -dSAFER flag does NOT prevent exploitation; do not rely on it as a mitigation indicator when triaging Ghostscript process activity. ↗
- ·Ghostscript versions prior to 9.18 are NOT vulnerable to code execution via this CVE; they may still be affected by directory traversal but not remote shell. ↗
- ·Ghostscript versions prior to 9.x (e.g., 8.70) lack ICC profile management entirely and are not affected by this CVE. ↗
- ·The -dSAFER flag is insufficient to prevent exploitation; path traversal and command execution remain possible even with this flag enabled. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9v96-pr6j-ghxc: The PS Interpreter in Ghostscript 9
ghsa_unreviewed·2022-05-17
CVE-2016-7976 [HIGH] CWE-20 GHSA-9v96-pr6j-ghxc: The PS Interpreter in Ghostscript 9
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
OSV
CVE-2016-7976: The PS Interpreter in Ghostscript 9
osv·2017-08-07·CVSS 8.8
CVE-2016-7976 [HIGH] CVE-2016-7976: The PS Interpreter in Ghostscript 9
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
OSV
ghostscript vulnerabilities
osv·2016-12-02·CVSS 5.5
CVE-2016-7976 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
Tavis Ormandy discovered multiple vulnerabilities in the way that Ghostscript
processes certain Postscript files. If a user or automated system were tricked
into opening a specially crafted file, an attacker could cause a denial of
service or possibly execute arbitrary code. (CVE-2016-7976, CVE-2016-7978,
CVE-2016-7979, CVE-2016-8602)
Multiple vulnerabilities were discovered in Ghostscript related to information
disclosure. If a user or automated system were tricked into opening a specially
crafted file, an attacker could expose sensitive data. (CVE-2013-5653,
CVE-2016-7977)
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2016-12-02·CVSS 5.5
CVE-2013-5653 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript could be made to crash, run programs, or disclose sensitive
information if it processed a specially crafted file.
Tavis Ormandy discovered multiple vulnerabilities in the way that Ghostscript
processes certain Postscript files. If a user or automated system were tricked
into opening a specially crafted file, an attacker could cause a denial of
service or possibly execute arbitrary code. (CVE-2016-7976, CVE-2016-7978,
CVE-2016-7979, CVE-2016-8602)
Multiple vulnerabilities were discovered in Ghostscript related to information
disclosure. If a user or automated system were tricked into opening a specially
crafted file, an attacker could expose sensitive data. (CVE-2013-5653,
CVE-2016-7977)
Instructions: In general, a standard system
Red Hat
ghostscript: various userparams allow %pipe% in paths, allowing remote shell
vendor_redhat·2016-09-30·CVSS 8.8
CVE-2016-7976 [HIGH] CWE-20 ghostscript: various userparams allow %pipe% in paths, allowing remote shell
ghostscript: various userparams allow %pipe% in paths, allowing remote shell
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
Package: ghostscript (Red Hat Enterprise Linux 5) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 6) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 7) - Not affected
Package: ghostscript (Red Hat OpenShift Enterprise 2) - Not affected
Debian
CVE-2016-7976: ghostscript - The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execu...
vendor_debian·2016·CVSS 8.8
CVE-2016-7976 [HIGH] CVE-2016-7976: ghostscript - The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execu...
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
Scope: local
bookworm: resolved (fixed in 9.19~dfsg-3.1)
bullseye: resolved (fixed in 9.19~dfsg-3.1)
forky: resolved (fixed in 9.19~dfsg-3.1)
sid: resolved (fixed in 9.19~dfsg-3.1)
trixie: resolved (fixed in 9.19~dfsg-3.1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
vendor_cisco
CVE-2015-7976 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
CVE-2015-7976: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On January 19, 2016, NTP Consortium at Network Time Foundation released a security advisory detailing 12 issues regarding multiple DoS vulnerabilities, information disclosure vulnerabilities, and logic issues that may allow an attacker to shift a client's time. The vulnerabilities covered in this document are as follows: CVE-
No detection rules found.
No public exploits indexed.
http://git.ghostscript.com/?p=user/chrisl/ghostpdl.git%3Ba=commit%3Bh=6d444c273da5499a4cd72f21cb6d4c9a5256807dhttp://www.debian.org/security/2016/dsa-3691http://www.openwall.com/lists/oss-security/2016/10/19/6http://www.securityfocus.com/bid/95332https://bugs.ghostscript.com/show_bug.cgi?id=697178https://security.gentoo.org/glsa/201702-31http://git.ghostscript.com/?p=user/chrisl/ghostpdl.git%3Ba=commit%3Bh=6d444c273da5499a4cd72f21cb6d4c9a5256807dhttp://www.debian.org/security/2016/dsa-3691http://www.openwall.com/lists/oss-security/2016/10/19/6http://www.securityfocus.com/bid/95332https://bugs.ghostscript.com/show_bug.cgi?id=697178https://security.gentoo.org/glsa/201702-31
2017-08-07
Published