First published: Wed Apr 19 2017(Updated: )
Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via a crafted PostScript document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Software Ghostscript | =9.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7948 is considered a high severity vulnerability due to its potential for causing application crashes and denial of service.
To fix CVE-2017-7948, update Ghostscript to version 9.22 or later, which has patched the vulnerability.
CVE-2017-7948 can lead to denial of service attacks by causing out-of-bounds write conditions, potentially crashing applications.
Users of Artifex Ghostscript version 9.21 are vulnerable to CVE-2017-7948.
CVE-2017-7948 can be exploited via a crafted PostScript document that triggers the vulnerability.