CVE-2017-5951
published 2017-04-03CVE-2017-5951: The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.85%
76.7th percentile
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | — | — |
| artifex | ghostscript | >= 0 < 9.20~dfsg-3.1 | 9.20~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.20~dfsg-3.1 | 9.20~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.20~dfsg-3.1 | 9.20~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.20~dfsg-3.1 | 9.20~dfsg-3.1 |
| artifex | ghostscript | >= 0 < 9.10~dfsg-0ubuntu10.7 | 9.10~dfsg-0ubuntu10.7 |
| artifex | ghostscript | >= 0 < 9.10~dfsg-0ubuntu10.9 | 9.10~dfsg-0ubuntu10.9 |
| artifex | ghostscript | >= 0 < 9.18~dfsg~0-0ubuntu2.4 | 9.18~dfsg~0-0ubuntu2.4 |
| artifex | ghostscript | >= 0 < 9.18~dfsg~0-0ubuntu2.6 | 9.18~dfsg~0-0ubuntu2.6 |
| debian | ghostscript | < ghostscript 9.20~dfsg-3.1 (bookworm) | ghostscript 9.20~dfsg-3.1 (bookworm) |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chwm-vq5f-3r66: The mem_get_bits_rectangle function in base/gdevmem
ghsa_unreviewed·2022-05-17
CVE-2017-5951 [MEDIUM] CWE-476 GHSA-chwm-vq5f-3r66: The mem_get_bits_rectangle function in base/gdevmem
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
OSV
ghostscript regression
osv·2017-05-16·CVSS 5.5
[MEDIUM] ghostscript regression
ghostscript regression
USN-3272-1 fixed vulnerabilities in Ghostscript. This change introduced
a regression when the DELAYBIND feature is used with the eqproc
command. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ghostscript improperly handled parameters to
the rsdparams and eqproc commands. An attacker could use these to
craft a malicious document that could disable -dSAFER protections,
thereby allowing the execution of arbitrary code, or cause a denial
of service (application crash). (CVE-2017-8291)
Kamil Frankowicz discovered a use-after-free vulnerability in the
color management module of Ghostscript. An attacker could use this
to cause a denial of service (application crash). (CVE-2016-10217)
Kamil Frankowic
OSV
ghostscript vulnerabilities
osv·2017-04-28·CVSS 5.5
CVE-2017-8291 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript improperly handled parameters to
the rsdparams and eqproc commands. An attacker could use these to
craft a malicious document that could disable -dSAFER protections,
thereby allowing the execution of arbitrary code, or cause a denial
of service (application crash). (CVE-2017-8291)
Kamil Frankowicz discovered a use-after-free vulnerability in the
color management module of Ghostscript. An attacker could use this
to cause a denial of service (application crash). (CVE-2016-10217)
Kamil Frankowicz discovered a divide-by-zero error in the scan
conversion code in Ghostscript. An attacker could use this to cause
a denial of service (application crash). (CVE-2016-10219)
Kamil Frankowicz discovered multiple NULL pointer dereference
OSV
CVE-2017-5951: The mem_get_bits_rectangle function in base/gdevmem
osv·2017-04-03·CVSS 5.5
CVE-2017-5951 [MEDIUM] CVE-2017-5951: The mem_get_bits_rectangle function in base/gdevmem
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Ubuntu
Ghostscript regression
vendor_ubuntu·2017-05-16·CVSS 5.5
[MEDIUM] Ghostscript regression
Title: Ghostscript regression
Summary: USN-3272-1 introduced a regression in Ghostscript.
USN-3272-1 fixed vulnerabilities in Ghostscript. This change introduced
a regression when the DELAYBIND feature is used with the eqproc
command. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ghostscript improperly handled parameters to
the rsdparams and eqproc commands. An attacker could use these to
craft a malicious document that could disable -dSAFER protections,
thereby allowing the execution of arbitrary code, or cause a denial
of service (application crash). (CVE-2017-8291)
Kamil Frankowicz discovered a use-after-free vulnerability in the
color management module of Ghostscript. An attacker could use this
to cause a deni
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2017-04-28·CVSS 5.5
CVE-2016-10217 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript improperly handled parameters to
the rsdparams and eqproc commands. An attacker could use these to
craft a malicious document that could disable -dSAFER protections,
thereby allowing the execution of arbitrary code, or cause a denial
of service (application crash). (CVE-2017-8291)
Kamil Frankowicz discovered a use-after-free vulnerability in the
color management module of Ghostscript. An attacker could use this
to cause a denial of service (application crash). (CVE-2016-10217)
Kamil Frankowicz discovered a divide-by-zero error in the scan
conversion code in Ghostscript. An attacker could use this to cause
a denial of service (application crash). (CVE-2016-10
Red Hat
ghostscript: NULL pointer dereference in the mem_get_bits_rectangle function
vendor_redhat·2017-02-03·CVSS 5.5
CVE-2017-5951 [MEDIUM] CWE-476 ghostscript: NULL pointer dereference in the mem_get_bits_rectangle function
ghostscript: NULL pointer dereference in the mem_get_bits_rectangle function
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Package: ghostscript (Red Hat Enterprise Linux 5) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 6) - Will not fix
Package: ghostscript (Red Hat Enterprise Linux 7) - Will not fix
Package: ghostscript (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2017-5951: ghostscript - The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. ...
vendor_debian·2017·CVSS 5.5
CVE-2017-5951 [MEDIUM] CVE-2017-5951: ghostscript - The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. ...
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 9.20~dfsg-3.1)
bullseye: resolved (fixed in 9.20~dfsg-3.1)
forky: resolved (fixed in 9.20~dfsg-3.1)
sid: resolved (fixed in 9.20~dfsg-3.1)
trixie: resolved (fixed in 9.20~dfsg-3.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5951 ghostscript: NULL pointer dereference in the mem_get_bits_rectangle function
bugzilla·2017-04-12·CVSS 5.5
CVE-2017-5951 [MEDIUM] CVE-2017-5951 ghostscript: NULL pointer dereference in the mem_get_bits_rectangle function
CVE-2017-5951 ghostscript: NULL pointer dereference in the mem_get_bits_rectangle function
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript allows attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Upstream patch:
http://git.ghostscript.com/?p=user/chrisl/ghostpdl.git;a=commitdiff;h=bfa6b2ec
Upstream bug:
https://bugs.ghostscript.com/show_bug.cgi?id=697548
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1441581]
Bugzilla
CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
bugzilla·2017-04-12·CVSS 5.5
CVE-2016-10217 [MEDIUM] CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
CVE-2016-10217 CVE-2016-10218 CVE-2016-10219 CVE-2016-10220 CVE-2016-10317 CVE-2017-5951 ghostscript: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
http://www.debian.org/security/2017/dsa-3838http://www.securityfocus.com/bid/98665https://bugs.ghostscript.com/show_bug.cgi?id=697548https://security.gentoo.org/glsa/201708-06http://www.debian.org/security/2017/dsa-3838http://www.securityfocus.com/bid/98665https://bugs.ghostscript.com/show_bug.cgi?id=697548https://security.gentoo.org/glsa/201708-06
2017-04-03
Published