CVE-2016-7979
published 2017-05-23CVE-2016-7979: Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type…
PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.42%
92.9th percentile
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | <= 9.20 | — |
| artifex | ghostscript | >= 0 < 9.19~dfsg-3.1 | 9.19~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.19~dfsg-3.1 | 9.19~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.19~dfsg-3.1 | 9.19~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.19~dfsg-3.1 | 9.19~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.10~dfsg-0ubuntu10.5 | 9.10~dfsg-0ubuntu10.5 |
| artifex | ghostscript | >= 0 < 9.18~dfsg~0-0ubuntu2.2 | 9.18~dfsg~0-0ubuntu2.2 |
| debian | ghostscript | < ghostscript 9.19~dfsg-3.1 (bookworm) | ghostscript 9.19~dfsg-3.1 (bookworm) |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwgm-gwqf-q8px: Ghostscript before 9
ghsa_unreviewed·2022-05-14
CVE-2016-7979 [CRITICAL] CWE-704 GHSA-vwgm-gwqf-q8px: Ghostscript before 9
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
OSV
CVE-2016-7979: Ghostscript before 9
osv·2017-05-23·CVSS 9.8
CVE-2016-7979 [CRITICAL] CVE-2016-7979: Ghostscript before 9
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
OSV
ghostscript vulnerabilities
osv·2016-12-02·CVSS 5.5
CVE-2016-7976 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
Tavis Ormandy discovered multiple vulnerabilities in the way that Ghostscript
processes certain Postscript files. If a user or automated system were tricked
into opening a specially crafted file, an attacker could cause a denial of
service or possibly execute arbitrary code. (CVE-2016-7976, CVE-2016-7978,
CVE-2016-7979, CVE-2016-8602)
Multiple vulnerabilities were discovered in Ghostscript related to information
disclosure. If a user or automated system were tricked into opening a specially
crafted file, an attacker could expose sensitive data. (CVE-2013-5653,
CVE-2016-7977)
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2016-12-02·CVSS 5.5
CVE-2013-5653 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript could be made to crash, run programs, or disclose sensitive
information if it processed a specially crafted file.
Tavis Ormandy discovered multiple vulnerabilities in the way that Ghostscript
processes certain Postscript files. If a user or automated system were tricked
into opening a specially crafted file, an attacker could cause a denial of
service or possibly execute arbitrary code. (CVE-2016-7976, CVE-2016-7978,
CVE-2016-7979, CVE-2016-8602)
Multiple vulnerabilities were discovered in Ghostscript related to information
disclosure. If a user or automated system were tricked into opening a specially
crafted file, an attacker could expose sensitive data. (CVE-2013-5653,
CVE-2016-7977)
Instructions: In general, a standard system
Red Hat
ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution
vendor_redhat·2016-10-04·CVSS 9.8
CVE-2016-7979 [CRITICAL] CWE-20 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution
ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
It was found that the ghostscript function .initialize_dsc_parser did not validate its parameter before using it, allowing a type confusion flaw. A specially crafted postscript document could cause a crash code execution in the context of the gs process.
Package: ghostscript (Red Hat Enterprise Linux 5) - Will not fix
Package: ghostscript (Red Hat OpenShift Enterprise 2) - Will not fix
Red Hat
ntp: bad authentication demobilizes ephemeral associations
vendor_redhat·2016-06-02·CVSS 7.5
CVE-2016-4953 [HIGH] ntp: bad authentication demobilizes ephemeral associations
ntp: bad authentication demobilizes ephemeral associations
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
Statement: This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they already included a fix for this issue in the patch provided to fix the CVE-2015-7979 issue. The fix for this issue (developed by Red Hat) was different from the one provided by upstream, and thus ntp versions in RHEL are not affected by CVE-2016-4953.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp (Red Hat Enterprise Lin
Debian
CVE-2016-7979: ghostscript - Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode pr...
vendor_debian·2016·CVSS 9.8
CVE-2016-7979 [CRITICAL] CVE-2016-7979: ghostscript - Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode pr...
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
Scope: local
bookworm: resolved (fixed in 9.19~dfsg-3.1)
bullseye: resolved (fixed in 9.19~dfsg-3.1)
forky: resolved (fixed in 9.19~dfsg-3.1)
sid: resolved (fixed in 9.19~dfsg-3.1)
trixie: resolved (fixed in 9.19~dfsg-3.1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
vendor_cisco
CVE-2015-7979 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
CVE-2015-7979: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On January 19, 2016, NTP Consortium at Network Time Foundation released a security advisory detailing 12 issues regarding multiple DoS vulnerabilities, information disclosure vulnerabilities, and logic issues that may allow an attacker to shift a client's time. The vulnerabilities covered in this document are as follows: CVE-
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7979 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution [fedora-all]
bugzilla·2016-11-01·CVSS 9.8
CVE-2016-7979 [CRITICAL] CVE-2016-7979 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution [fedora-all]
CVE-2016-7979 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2016-7979 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution
bugzilla·2016-10-06·CVSS 9.8
CVE-2016-7979 [CRITICAL] CVE-2016-7979 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution
CVE-2016-7979 ghostscript: Type confusion in .initialize_dsc_parser allows remote code execution
.initialize_dsc_parser doesn't validate the parameter is a dict type before using it.
This is a security issue, because it can be abused to escape the -dSAFER sandbox.
This allows a Denial of Service, arbitrary code execution.
Upstream bug :
- Bug 697190 - .initialize_dsc_parser doesn't validate the parameter is a dict type before using it.
http://bugs.ghostscript.com/show_bug.cgi?id=697190
Upstream patch :
- DSC parser - validate parameters
http://git.ghostscript.com/?p=ghostpdl.git;h=875a0095f37626a721c7ff57d606a0f95af03913
Reference :
http://seclists.org/oss-sec/2016/q4/37
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1390489]
---
This issu
Bugzilla
CVE-2016-4953 ntp: bad authentication demobilizes ephemeral associations
bugzilla·2016-05-30·CVSS 7.5
CVE-2016-4953 [HIGH] CVE-2016-4953 ntp: bad authentication demobilizes ephemeral associations
CVE-2016-4953 ntp: bad authentication demobilizes ephemeral associations
It was found that the fixes for CVE-2015-7979 and CVE-2016-1547 were incomplete: An attacker can send a spoofed packet that contains an invalid MAC to a client/peer and demobilize its ephemeral association.
Discussion:
Acknowledgments:
Name: Miroslav Lichvar (Red Hat)
---
Statement:
This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they already included a fix for this issue in the patch provided to fix the CVE-2015-7979 issue. The fix for this issue (developed by Red Hat) was different from the one provided by upstream, and thus ntp versions in RHEL are not affected by CVE-2016-4953.
---
Upstream bug:
http://support.ntp.org/bin/view/Main/NtpBug3045
Externa
http://git.ghostscript.com/?p=ghostpdl.git%3Bh=875a0095f37626a721c7ff57d606a0f95af03913http://rhn.redhat.com/errata/RHSA-2017-0013.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0014.htmlhttp://www.debian.org/security/2016/dsa-3691http://www.openwall.com/lists/oss-security/2016/10/05/15http://www.securityfocus.com/bid/95337https://bugs.ghostscript.com/show_bug.cgi?id=697190https://security.gentoo.org/glsa/201702-31http://git.ghostscript.com/?p=ghostpdl.git%3Bh=875a0095f37626a721c7ff57d606a0f95af03913http://rhn.redhat.com/errata/RHSA-2017-0013.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0014.htmlhttp://www.debian.org/security/2016/dsa-3691http://www.openwall.com/lists/oss-security/2016/10/05/15http://www.securityfocus.com/bid/95337https://bugs.ghostscript.com/show_bug.cgi?id=697190https://security.gentoo.org/glsa/201702-31
2017-05-23
Published