Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ghostscript-debuginfoUpgrade ghostscript-cupsUpgrade ghostscriptUpgrade ghostscript-docUpgrade ghostscript-gtkUpgrade ghostscript-devel | Jan 27, 2017 | Oct 11, 2016 |
| Debian | — | Upgrade ghostscript | Mar 31, 2017 | Oct 11, 2016 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Oct 30, 2017 | May 23, 2017 |
| Ghostscript | — | Upgrade to Ghostscript version 9.21 | Oct 10, 2018 | May 23, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Nov 30, 2017 | May 23, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4Upgrade print/filter/ghostscript to version 9.26-0.175.3.36.0.10.0 on Solaris 11.3 | Oct 19, 2018 | May 23, 2017 |
| Oracle_linux | — | Upgrade ghostscript-docUpgrade ghostscript-develUpgrade ghostscript-gtkUpgrade ghostscriptUpgrade ghostscript-cups | Jan 5, 2017 | Sep 30, 2016 |
| Redhat_linux | — | Upgrade ghostscript-cupsUpgrade ghostscript-gtkUpgrade ghostscript-debuginfoUpgrade ghostscript-docUpgrade ghostscriptUpgrade ghostscript-devel | Jan 5, 2017 | Oct 11, 2016 |
| Suse | — | Upgrade ghostscript-develUpgrade ghostscriptUpgrade ghostscript-x11 | Nov 3, 2016 | Oct 11, 2016 |
| Ubuntu | — | Upgrade ghostscript-xUpgrade ghostscriptUpgrade libgs9Upgrade libgs9-common | Dec 2, 2016 | Oct 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub