First published: Mon Aug 07 2017(Updated: )
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Software Ghostscript | =9.18 | |
Artifex Software Ghostscript | =9.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7976 is classified as a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2016-7976, update Ghostscript to version 9.21 or later.
CVE-2016-7976 affects Ghostscript versions 9.18 and 9.20.
Yes, CVE-2016-7976 can be exploited remotely by attackers through crafted userparams.
There are no widely recommended workarounds for CVE-2016-7976; the best course is to update the software.