CVE-2017-11714: High severity Artifex Ghostscript vulnerability
psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, related to an out-of-bounds read in the igcrelocstructptr function in psi/igc.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11714?
CVE-2017-11714 has a moderate severity level due to its potential to cause denial of service.
How do I fix CVE-2017-11714?
To fix CVE-2017-11714, update to Ghostscript version 9.22 or later, which includes the necessary patches.
What software is affected by CVE-2017-11714?
CVE-2017-11714 affects Artifex Ghostscript version 9.21, as well as Debian Linux versions 8.0 and 9.0.
What type of attack does CVE-2017-11714 allow?
CVE-2017-11714 allows remote attackers to cause application crashes through crafted PostScript documents.
Is CVE-2017-11714 exploitable by unauthenticated users?
Yes, CVE-2017-11714 can be exploited by unauthenticated users who can submit crafted PostScript documents.