CVE-2020-16289: Buffer Overflow
A buffer overflow vulnerability in cifprintpage() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 9.53.3~dfsg-7+deb11u7Fixed in 9.53.3~dfsg-7+deb11u10Fixed in 10.0.0~dfsg-11+deb12u6Fixed in 10.0.0~dfsg-11+deb12u7Fixed in 10.05.0~dfsg-1 - Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 9.51 - Upgrade
Upgrade
Artifex Software GhostScriptto a version that resolves this vulnerability.Fixed in 9.51
Event History
Frequently Asked Questions
What is CVE-2020-16289?
CVE-2020-16289 is a buffer overflow vulnerability in cif_print_page() in Artifex Software GhostScript v9.50.
How can a remote attacker exploit CVE-2020-16289?
A remote attacker can exploit CVE-2020-16289 by sending a crafted PDF file, causing a denial of service.
What is the severity of CVE-2020-16289?
CVE-2020-16289 has a severity rating of medium (5.5).
How do I fix CVE-2020-16289?
To fix CVE-2020-16289, update Artifex Software GhostScript to version 9.51 or later.
Where can I find more information about CVE-2020-16289?
You can find more information about CVE-2020-16289 in the references provided: [link1](https://bugs.ghostscript.com/show_bug.cgi?id=701788), [link2](https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=d31e25ed5b130499e0d880e4609b1b4824699768), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1870245).