CVE-2017-6196: Use After Free
Multiple use-after-free vulnerabilities in the gximageenumbegin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6196?
CVE-2017-6196 has been classified as a denial of service vulnerability due to its potential to cause application crashes.
How do I fix CVE-2017-6196?
To mitigate CVE-2017-6196, update Ghostscript to the latest version that includes the patch for this vulnerability.
What types of attacks can exploit CVE-2017-6196?
CVE-2017-6196 can be exploited through crafted PostScript documents that trigger the use-after-free vulnerabilities.
Which software versions are affected by CVE-2017-6196?
CVE-2017-6196 affects Ghostscript versions prior to the commit ecceafe3abba2714ef9b432035fe0739d9b1a283.
Are there any known impacts of CVE-2017-6196 beyond application crashes?
While the primary impact of CVE-2017-6196 is a denial of service, there may be unspecified other impacts due to the nature of the vulnerability.