SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-7977

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

MEDIUM 5.5EPSS 4.57%

Does this matter?

Lower severity and a low EPSS score (4.57%). Track it; it rarely justifies an emergency change on its own.

Description

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

CVSS 3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
4.57% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
artifex/ghostscript
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.