CVE-2020-16293 PUBLISHED

A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

EPSS 1.31% · 79.7th percentile

Risk Scores

EPSS Score
1.31%
79.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSghostscript0, 9.50~dfsg-5ubuntu4.1, 9.50~dfsg-5ubuntu4
Ubuntu:18.04:LTSghostscript9.25~dfsg+1-0ubuntu0.18.04.2, 0, 9.21~dfsg+1-0ubuntu3
Ubuntu:16.04:LTSghostscript9.16~dfsg~0-0ubuntu3, 9.18~dfsg~0-0ubuntu2.6, 9.18~dfsg~0-0ubuntu2.4

Timeline

References

Open in Interactive Console →