CVE-2017-9740: High severity ghostscript vulnerability
The xpsdecodefontcharimp function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9740?
CVE-2017-9740 is classified as a high severity vulnerability as it allows remote attackers to cause denial of service through heap-based buffer over-read.
How do I fix CVE-2017-9740?
To fix CVE-2017-9740, you should upgrade to a patched version of Artifex Ghostscript that resolves this vulnerability.
What type of impact does CVE-2017-9740 have?
CVE-2017-9740 can lead to application crashes and potentially other unspecified impacts from crafted documents.
Which versions of Ghostscript are affected by CVE-2017-9740?
CVE-2017-9740 affects Artifex Ghostscript GhostXPS version 9.21.
Is CVE-2017-9740 a remote code execution vulnerability?
No, CVE-2017-9740 is not a remote code execution vulnerability; it primarily causes denial of service.