CVE-2016-7976: Input Validation
Published Aug 7, 2017
·Updated
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
Affected Software
2 affected components
Artifex ghostscript=9.18
Artifex ghostscript=9.20
Event History
Aug 7, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7976?
CVE-2016-7976 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2016-7976?
To fix CVE-2016-7976, update Ghostscript to version 9.21 or later.
3
What versions of Ghostscript are affected by CVE-2016-7976?
CVE-2016-7976 affects Ghostscript versions 9.18 and 9.20.
4
Can CVE-2016-7976 be exploited remotely?
Yes, CVE-2016-7976 can be exploited remotely by attackers through crafted userparams.
5
Is there a known workaround for CVE-2016-7976?
There are no widely recommended workarounds for CVE-2016-7976; the best course is to update the software.