CVE-2017-7207: Null Pointer Dereference
A null pointer vulnerability was found in memgetbitsrectangle() when trying to read from unallocated memory.
Upstream bug:
https://bugs.ghostscript.com/showbug.cgi?id=697676
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;h=309eca4e0a31ea70dcc844812691439312dad091
Other sources
The memgetbitsrectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7207?
CVE-2017-7207 is classified as a denial of service vulnerability due to a NULL pointer dereference.
How do I fix CVE-2017-7207?
To mitigate CVE-2017-7207, users should upgrade to a later version of Ghostscript beyond 9.20, where the vulnerability is addressed.
What software is affected by CVE-2017-7207?
CVE-2017-7207 specifically affects Ghostscript version 9.20.
Can CVE-2017-7207 be exploited remotely?
Yes, CVE-2017-7207 can be exploited remotely through crafted PostScript documents.
What type of vulnerability is CVE-2017-7207?
CVE-2017-7207 is a NULL pointer dereference vulnerability that leads to a denial of service.