CVE-2017-9727: High severity ghostscript vulnerability
Published Jul 26, 2017
·Updated
The gxttfReaderRead function in base/gxttfb.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
Affected Software
3 affected components
Artifex Ghostscript GhostXPS=9.21
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Jul 26, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9727?
CVE-2017-9727 has a medium severity rating as it can lead to denial of service through application crashes.
2
How do I fix CVE-2017-9727?
To fix CVE-2017-9727, upgrade to Ghostscript GhostXPS version 9.22 or later.
3
What causes the vulnerability CVE-2017-9727?
CVE-2017-9727 is caused by a heap-based buffer over-read in the gx_ttfReader__Read function.
4
Is CVE-2017-9727 exploitable over the network?
Yes, CVE-2017-9727 can be exploited by remote attackers via crafted documents.
5
Which software versions are affected by CVE-2017-9727?
CVE-2017-9727 affects Artifex Ghostscript GhostXPS version 9.21 and specific versions of Debian GNU/Linux.