Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function in jbig2_huffman.c during operations on a crafted JBIG2 file, leading to a denial of service (application crash) or possibly execution of arbitrary code.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jbig2dec | May 15, 2017 | Apr 19, 2017 |
| Gentoo Linux | — | Upgrade media-libs/jbig2dec. | Oct 30, 2017 | Apr 19, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Dec 4, 2019 | Apr 19, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Dec 18, 2019 | Apr 19, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Dec 11, 2019 | Apr 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 27, 2017 |
| Ubuntu | — | Upgrade libjbig2dec0Upgrade jbig2dec | May 25, 2017 | Apr 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub