The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ghostscript | Mar 31, 2017 | Oct 12, 2016 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Oct 30, 2017 | Aug 7, 2017 |
| Ghostscript | — | Upgrade to Ghostscript version 9.21 | Oct 10, 2018 | Aug 7, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Sep 16, 2021 | Aug 7, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Apr 30, 2021 | Aug 7, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Nov 19, 2019 | Aug 7, 2017 |
| Oracle Solaris | — | Upgrade print/filter/ghostscript to version 9.26-0.175.3.36.0.10.0 on Solaris 11.3Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Aug 7, 2017 |
| Suse | — | Upgrade ghostscriptUpgrade ghostscript-x11Upgrade ghostscript-devel | May 20, 2018 | Dec 1, 2016 |
| Ubuntu | — | Upgrade ghostscript-xUpgrade libgs9Upgrade libgs9-commonUpgrade ghostscript | Dec 2, 2016 | Dec 1, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub