VulnerabilityModified
CVE-2016-7977
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.
MEDIUM 5.5EPSS 4.57%
Does this matter?
Lower severity and a low EPSS score (4.57%). Track it; it rarely justifies an emergency change on its own.
Description
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 4.57% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- artifex/ghostscript
- Source
- cve@mitre.org
References
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=8abd22010eb4db0fb1b10e430d5f5d83e015ef70
- http://rhn.redhat.com/errata/RHSA-2017-0013.html
- http://rhn.redhat.com/errata/RHSA-2017-0014.html
- http://www.debian.org/security/2016/dsa-3691
- http://www.openwall.com/lists/oss-security/2016/09/29/28Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2016/10/05/15Mailing List, Patch
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.securityfocus.com/bid/95334Third Party Advisory, VDB Entry
- https://bugs.ghostscript.com/show_bug.cgi?id=697169Issue Tracking, Patch
- https://ghostscript.com/doc/9.21/History9.htmRelease Notes
- https://security.gentoo.org/glsa/201702-31
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=8abd22010eb4db0fb1b10e430d5f5d83e015ef70
- http://rhn.redhat.com/errata/RHSA-2017-0013.html
- http://rhn.redhat.com/errata/RHSA-2017-0014.html
- http://www.debian.org/security/2016/dsa-3691
- http://www.openwall.com/lists/oss-security/2016/09/29/28Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2016/10/05/15Mailing List, Patch
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.securityfocus.com/bid/95334Third Party Advisory, VDB Entry
- https://bugs.ghostscript.com/show_bug.cgi?id=697169Issue Tracking, Patch
- https://ghostscript.com/doc/9.21/History9.htmRelease Notes
- https://security.gentoo.org/glsa/201702-31
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.