cbcvebase.
CVE-2016-7979
published 2017-05-23

CVE-2016-7979: Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

Affected

8 ranges
VendorProductVersion rangeFixed in
artifexghostscript<= 9.20
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.10~dfsg-0ubuntu10.59.10~dfsg-0ubuntu10.5
artifexghostscript>= 0 < 9.18~dfsg~0-0ubuntu2.29.18~dfsg~0-0ubuntu2.2
debianghostscript< ghostscript 9.19~dfsg-3.1 (bookworm)ghostscript 9.19~dfsg-3.1 (bookworm)

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL