CVE-2020-15900: Integer Underflow
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15900?
CVE-2020-15900 is a memory corruption vulnerability found in Artifex Ghostscript 9.50 and 9.52.
What is the severity of CVE-2020-15900?
The severity of CVE-2020-15900 is critical with a CVSS score of 9.8.
What is the affected software of CVE-2020-15900?
The affected software includes Artifex Ghostscript versions 9.50 and 9.52, as well as Ubuntu Linux 20.04 and openSUSE Leap 15.1/15.2.
How can the vulnerability be exploited?
The vulnerability can be exploited by using a non-standard PostScript operator to override file access controls.
Is there a fix available for CVE-2020-15900?
Yes, there are fixes available. Please refer to the provided references for more information on the fixes.