cbcvebase.
CVE-2016-8602
published 2017-04-14

CVE-2016-8602: The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service (application crash) or possibly…

high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Postscript document that calls .sethalftone5 with an empty operand stack.

Affected

8 ranges
VendorProductVersion rangeFixed in
artifexghostscript<= 9.20
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.19~dfsg-3.19.19~dfsg-3.1
artifexghostscript>= 0 < 9.10~dfsg-0ubuntu10.59.10~dfsg-0ubuntu10.5
artifexghostscript>= 0 < 9.18~dfsg~0-0ubuntu2.29.18~dfsg~0-0ubuntu2.2
debianghostscript< ghostscript 9.19~dfsg-3.1 (bookworm)ghostscript 9.19~dfsg-3.1 (bookworm)

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH