VDB
GCVE-VVD-MAGEIA-2017-133
GCVE-VVD-MAGEIA-2017-133
Advisory Published
Various userparams in Ghostscript allow %pipe% in paths, allowing remote
shell command execution (CVE-2016-7976).
The .libfile function in Ghostscript doesn't check PermitFileReading
array, allowing remote file disclosure (CVE-2016-7977).
Reference leak in the .setdevice function in Ghostscript allows
use-after-free and remote code execution (CVE-2016-7978).
Type confusion in the .initialize_dsc_parser function in Ghostscript
allows remote code execution (CVE-2016-7979).
The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21
allows remote attackers to cause a denial of service (application crash)
or possibly execute arbitrary code via a crafted Postscript document
that calls .sethalftone5 with an empty operand stack (CVE-2016-8602).
A heap based buffer overflow was found in the ghostscript
jbig2_decode_gray_scale_image() function used to decode halftone segments
in a JBIG2 image. A document (PostScript or PDF) with an embedded,
specially crafted, jbig2 image could trigger a segmentation fault in
ghostscript (CVE-2016-9601).
The pdf14_open function in base/gdevp14.c in Ghostscript 9.20 allows
remote attackers to cause a denial of service (use-after-free and
application crash) via a crafted file that is mishandled in the color
management module (CVE-2016-10217).
The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF
Transparency module in Ghostscript 9.20 allows remote attackers to cause
a denial of service (NULL pointer dereference and application crash) via
a crafted file (CVE-2016-10218).
The intersect function in base/gxfill.c in Ghostscript 9.20 allows
remote attackers to cause a denial of service (divide-by-zero error and
application crash) via a crafted file (CVE-2016-10219).
The gs_makewordimagedevice function in base/gsdevmem.c in Ghostscript
9.20 allows remote attackers to cause a denial of service (NULL pointer
dereference and application crash) via a crafted file that is mishandled
in the PDF Transparency module (CVE-2016-10220).
The mem_get_bits_rectangle function in base/gdevmem.c in Ghostscript
9.20 allows remote attackers to cause a denial of service (NULL pointer
dereference and application crash) via a crafted file (CVE-2017-5951).
The mem_get_bits_rectangle function in Ghostscript 9.20 allows remote
attackers to cause a denial of service (NULL pointer dereference) via a
crafted PostScript document (CVE-2017-7207).
Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command
execution via .rsdparams type confusion with a "/OutputFile (%pipe%"
substring in a crafted .eps document that is an input to the gs program
(CVE-2017-8291).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | lensfun | 0 (affected), 0.3.2-2.2.mga6 (unaffected) | — |
| Mageia | ghostscript | 0 (affected), 9.20-1.mga5 (unaffected), 0 (affected), 9.20-1.mga5 (unaffected) | — |
| Mageia | gutenprint | 0 (affected), 5.2.10-5.1.mga5 (unaffected), 0 (affected), 5.2.10-5.1.mga5 (unaffected) | — |
| Mageia | libspectre | 0 (affected), 0.2.7-5.1.mga5 (unaffected), 0 (affected), 0.2.7-5.1.mga5 (unaffected) | — |
Aliases
CVE-2016-10219CVE-2016-9601CVE-2016-10217CVE-2017-5951CVE-2016-10220CVE-2016-7978CVE-2017-7207CVE-2016-7976CVE-2016-10218
Transitive aliases
GHSA-8rh8-m25j-rhmpEUVD-2016-8826GHSA-2gqv-9xv4-43w4GHSA-vf87-jj8q-h556CNVD-2016-09581GSD-2016-7976GHSA-9rxh-wvvf-hh9jCNVD-2017-06032GSD-2017-7885GHSA-458q-p5fc-j68hCNVD-2017-06134GHSA-jp8p-fj2v-5982GHSA-3g8x-c82p-r7gjEUVD-2016-8824GHSA-9v96-pr6j-ghxcEUVD-2016-1402CVE-2017-7975GHSA-h247-9cp2-w26hGSD-2016-7978EUVD-2016-1404EUVD-2016-1403CVE-2017-7885EUVD-2017-16860GSD-2017-7975CNVD-2016-09583EUVD-2016-10405GHSA-rhh2-326j-w4xrEUVD-2017-16945EUVD-2016-1405CVE-2017-7976GHSA-chwm-vq5f-3r66EUVD-2017-15021EUVD-2017-16243GHSA-64cw-wmc5-j274EUVD-2017-16946VVD-MAGEIA-2017-206
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.