CVE-2017-9620: High severity Artifex Ghostscript GhostXPS vulnerability
Published Jul 26, 2017
·Updated
The xpsselectfontencoding function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document, related to the xpsencodefontcharimp function.
Affected Software
1 affected component
Artifex Ghostscript GhostXPS=9.21
Event History
Jul 26, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9620?
The severity of CVE-2017-9620 is rated as high with a score of 7.8.
2
How do I fix CVE-2017-9620?
To fix CVE-2017-9620, you should upgrade to a version of Artifex Ghostscript GhostXPS later than 9.21.
3
What impact does CVE-2017-9620 have on my system?
CVE-2017-9620 can cause a denial of service due to a heap-based buffer over-read and potential application crashes.
4
Which versions of Artifex Ghostscript are affected by CVE-2017-9620?
CVE-2017-9620 affects Artifex Ghostscript GhostXPS version 9.21.
5
Can CVE-2017-9620 be exploited remotely?
Yes, CVE-2017-9620 can be exploited by remote attackers through crafted documents.