CVE-2020-14373: Use After Free
A use after free was found in igcrelocstructptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.
Other sources
When a crafted PDF is supplied to ghostscript-9.25, it triggers a use-after-free in igcrelocstructptr() of psi/igc.c on line 1279.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 9.26
Event History
Frequently Asked Questions
What is CVE-2020-14373?
CVE-2020-14373 is a vulnerability that allows a local attacker to cause a denial of service in Ghostscript 9.25.
How does CVE-2020-14373 work?
CVE-2020-14373 is caused by a use after free vulnerability in igc_reloc_struct_ptr() of psi/igc.c in Ghostscript 9.25, which can be exploited by a specially crafted PDF file.
What is the severity of CVE-2020-14373?
The severity of CVE-2020-14373 is medium with a CVSS score of 5.5.
What is the affected software for CVE-2020-14373?
The affected software for CVE-2020-14373 is Ghostscript 9.25 running on Redhat Enterprise Linux 7.0 and 8.0.
How can CVE-2020-14373 be fixed?
CVE-2020-14373 can be fixed by updating Ghostscript to version 9.26.