CVE-2017-8908: Medium severity ghostscript vulnerability
Published May 12, 2017
·Updated
The marklinetr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.
Affected Software
1 affected component
Artifex ghostscript=9.21
Remediation
Patch Available
Event History
May 12, 2017
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8908?
CVE-2017-8908 has been rated as a moderate severity vulnerability due to its potential to cause denial of service through out-of-bounds reads.
2
How do I fix CVE-2017-8908?
To fix CVE-2017-8908, users should upgrade to a newer version of Ghostscript beyond 9.21 that addresses this issue.
3
What type of attack does CVE-2017-8908 allow?
CVE-2017-8908 allows remote attackers to execute a denial of service attack through specially crafted PostScript documents.
4
Which software versions are affected by CVE-2017-8908?
CVE-2017-8908 affects Artifex Ghostscript version 9.21.
5
Can CVE-2017-8908 be exploited remotely?
Yes, CVE-2017-8908 can be exploited remotely through the delivery of malicious PostScript documents.