Your submission was sent successfully! Close

CVE-2016-10220

Published: 3 April 2017

The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.

Priority

Low

CVSS 3 base score: 5.5

Status

Package Release Status
ghostscript
Launchpad, Ubuntu, Debian
precise Does not exist
(precise was released [9.05~dfsg-0ubuntu4.5])
trusty Does not exist
(trusty was released [9.10~dfsg-0ubuntu10.7])
upstream Needed

xenial
Released (9.18~dfsg~0-0ubuntu2.4)
yakkety
Released (9.19~dfsg+1-0ubuntu6.4)
zesty
Released (9.19~dfsg+1-0ubuntu7.2)
Patches:
upstream: http://www.ghostscript.com/cgi-bin/findgit.cgi?daf85701dab05f17e924a48a81edc9195b4a04e8