CVE-2017-9610: High severity Artifex Ghostscript GhostXPS vulnerability
The xpsloadsfntname function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9610?
CVE-2017-9610 has been classified as a denial of service vulnerability.
How do I fix CVE-2017-9610?
To fix CVE-2017-9610, upgrade to a patched version of Artifex Ghostscript GhostXPS later than 9.21.
What types of attacks can CVE-2017-9610 facilitate?
CVE-2017-9610 can facilitate remote attacks resulting in a denial of service through heap-based buffer over-read.
Which version of Artifex Ghostscript is affected by CVE-2017-9610?
CVE-2017-9610 specifically affects Artifex Ghostscript GhostXPS version 9.21.
Can CVE-2017-9610 result in data exposure?
While CVE-2017-9610 primarily leads to application crashes, it may potentially have unspecified impacts, including risks of data exposure.