ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jbig2dec | Mar 25, 2017 | Mar 24, 2017 |
| Gentoo Linux | — | Upgrade media-libs/jbig2dec. | Oct 30, 2017 | Jun 22, 2017 |
| Ghostscript | — | Upgrade to Ghostscript version 9.22 | Oct 10, 2018 | Apr 23, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Sep 16, 2021 | Apr 24, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Dec 18, 2019 | Apr 24, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Dec 11, 2019 | Apr 24, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 24, 2018 |
| Suse | — | Upgrade libgimpprintUpgrade ghostscript-omniUpgrade ghostscript-libraryUpgrade ghostscript-ijs-develUpgrade ghostscript-fonts-otherUpgrade ghostscript-fonts-stdUpgrade ghostscript-x11Upgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-fonts-rusUpgrade libgimpprint-devel | May 2, 2017 | Mar 24, 2017 |
| Ubuntu | — | Upgrade libjbig2dec0Upgrade jbig2dec | May 25, 2017 | Mar 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub