CVE-2016-10220: Null Pointer Dereference
The gsmakewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10220?
CVE-2016-10220 has a severity rating that indicates it can lead to a denial of service due to a NULL pointer dereference.
How do I fix CVE-2016-10220?
To fix CVE-2016-10220, you should upgrade to a later version of Ghostscript that addresses this vulnerability.
Which versions of Ghostscript are affected by CVE-2016-10220?
Ghostscript version 9.20 is the affected version for CVE-2016-10220.
What type of attack does CVE-2016-10220 enable?
CVE-2016-10220 enables remote attackers to cause a denial of service by exploiting a bug in the PDF Transparency module.
Is CVE-2016-10220 specific to any platform?
CVE-2016-10220 is specific to the Ghostscript software developed by Artifex Software, Inc.