CVE-2016-10218: Null Pointer Dereference
Published Apr 3, 2017
·Updated
The pdf14poptransparencygroup function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Affected Software
1 affected component
Artifex ghostscript=9.20
Remediation
Patch Available
Event History
Apr 3, 2017
CVE Published
via MITRE·05:44 AM
Data Sourced
via MITRE·05:44 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10218?
CVE-2016-10218 has a severity rating that indicates it can lead to a denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2016-10218?
To resolve CVE-2016-10218, upgrading to a later version of Ghostscript than 9.20 is recommended.
3
Who is affected by CVE-2016-10218?
CVE-2016-10218 affects users and systems running Ghostscript version 9.20.
4
What type of attack does CVE-2016-10218 facilitate?
CVE-2016-10218 enables remote attackers to cause a denial of service by exploiting a crafted PDF file.
5
What does CVE-2016-10218 affect in Ghostscript?
CVE-2016-10218 specifically affects the PDF Transparency module in Ghostscript.