CVE-2020-16290: Buffer Overflow
A buffer overflow vulnerability in jetp3852printpage() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 0:9.27-1.el8 - Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 9.53.3~dfsg-7+deb11u7Fixed in 9.53.3~dfsg-7+deb11u10Fixed in 10.0.0~dfsg-11+deb12u6Fixed in 10.0.0~dfsg-11+deb12u7Fixed in 10.05.0~dfsg-1 - Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 9.51 - Upgrade
Upgrade
Artifex Software GhostScriptto a version that resolves this vulnerability.Fixed in 9.51
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-16290.
What is the severity of CVE-2020-16290?
The severity of CVE-2020-16290 is medium with a severity value of 5.5.
How does CVE-2020-16290 affect Artifex Software GhostScript?
CVE-2020-16290 allows a remote attacker to cause a denial of service in Artifex Software GhostScript v9.50 through a crafted PDF file.
How can the buffer overflow vulnerability CVE-2020-16290 be fixed?
The buffer overflow vulnerability CVE-2020-16290 can be fixed by updating Artifex Software GhostScript to v9.51.
Are there any references for CVE-2020-16290?
Yes, the references for CVE-2020-16290 are: [1](http://git.ghostscript.com/?p=ghostpdl.git;h=93cb0c0adbd9bcfefd021d59c472388f67d3300d), [2](https://bugs.ghostscript.com/show_bug.cgi?id=701786), [3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1870150).