CVE-2016-7978: Use After Free
Published May 23, 2017
·Updated
Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.
Affected Software
1 affected component
Artifex ghostscript=9.20
Remediation
Patch Available
Patch Available
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7978?
CVE-2016-7978 is classified as a critical severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2016-7978?
To fix CVE-2016-7978, upgrade Ghostscript to version 9.21 or later where the vulnerability has been addressed.
3
What software is affected by CVE-2016-7978?
CVE-2016-7978 specifically affects Ghostscript version 9.20.
4
Can CVE-2016-7978 be exploited remotely?
Yes, CVE-2016-7978 can be exploited remotely, enabling attackers to execute arbitrary code.
5
What type of vulnerability is CVE-2016-7978?
CVE-2016-7978 is a use-after-free vulnerability that results from a reference leak in Ghostscript.