CVE-2020-27792
published 2022-08-19CVE-2020-27792: A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to…
PriorityP427high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
EPSS
0.45%
36.4th percentile
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | <= 9.50 | — |
| artifex | ghostscript | >= 0 < 9.51~dfsg-1 | 9.51~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.51~dfsg-1 | 9.51~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.51~dfsg-1 | 9.51~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.51~dfsg-1 | 9.51~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.18.04.17 | 9.26~dfsg+0-0ubuntu0.18.04.17 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.6 | 9.50~dfsg-5ubuntu4.6 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.1 | 9.55.0~dfsg1-0ubuntu5.1 |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 9.51~dfsg-1 (bookworm) | ghostscript 9.51~dfsg-1 (bookworm) |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ghostscript vulnerabilities
osv·2022-09-27·CVSS 7.1
CVE-2020-27792 [HIGH] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that GhostScript incorrectly handled certain PDF files.
If a user or automated system were tricked into opening a specially crafted
PDF file, a remote attacker could use this issue to cause GhostScript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2020-27792)
It was discovered that GhostScript incorrectly handled certain PDF files.
If a user or automated system were tricked into opening a specially crafted
PDF file, a remote attacker could use this issue to cause GhostScript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2085)
GHSA
GHSA-7h9w-vh8m-rj5g: A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k
ghsa_unreviewed·2022-08-20
CVE-2020-27792 [HIGH] CWE-119 GHSA-7h9w-vh8m-rj5g: A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k
A heap-based buffer over write vulnerability was found in GhostScript's lp8000_print_page() function in gdevlp8k.c file. An attacker could trick a user to open a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
OSV
CVE-2020-27792: A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k
osv·2022-08-19·CVSS 7.1
CVE-2020-27792 [HIGH] CVE-2020-27792: A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2022-09-27·CVSS 7.1
CVE-2022-2085 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that GhostScript incorrectly handled certain PDF files.
If a user or automated system were tricked into opening a specially crafted
PDF file, a remote attacker could use this issue to cause GhostScript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2020-27792)
It was discovered that GhostScript incorrectly handled certain PDF files.
If a user or automated system were tricked into opening a specially crafted
PDF file, a remote attacker could use this issue to cause GhostScript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affec
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2022-09-20
CVE-2020-27792 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash if it opened a specially crafted.
It was discovered the Ghostscript incorrectly handled memory when
processing certain inputs. By tricking a user into opening a specially
crafted PDF file, an attacker could cause the program to crash.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-27792: ghostscript - A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_pr...
vendor_debian·2020·CVSS 7.1
CVE-2020-27792 [HIGH] CVE-2020-27792: ghostscript - A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_pr...
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: resolved (fixed in 9.51~dfsg-1)
trixie: resolved (fixed in 9.51~dfsg-1)
Red Hat
ghostscript: heap buffer over write vulnerability in GhostScript's lp8000_print_page() in gdevlp8k.c
vendor_redhat·2019-11-06·CVSS 7.1
CVE-2020-27792 [HIGH] CWE-119 ghostscript: heap buffer over write vulnerability in GhostScript's lp8000_print_page() in gdevlp8k.c
ghostscript: heap buffer over write vulnerability in GhostScript's lp8000_print_page() in gdevlp8k.c
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options d
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2025:4362https://access.redhat.com/security/cve/CVE-2020-27792https://bugzilla.redhat.com/show_bug.cgi?id=2247179https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4f6bc662909ab79e8fbe9822afb36e8a0eafc2b7https://access.redhat.com/security/cve/CVE-2020-27792https://bugs.ghostscript.com/show_bug.cgi?id=701844https://bugzilla.redhat.com/show_bug.cgi?id=2247179https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=4f6bc662909ab79e8fbe9822afb36e8a0eafc2b7https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4f6bc662909ab79e8fbe9822afb36e8a0eafc2b7https://lists.debian.org/debian-lts-announce/2022/09/msg00005.html
2022-08-19
Published