CVE-2020-16295: Null Pointer Dereference
A null pointer dereference vulnerability in cljmediasize() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 9.53.3~dfsg-7+deb11u7Fixed in 9.53.3~dfsg-7+deb11u10Fixed in 10.0.0~dfsg-11+deb12u6Fixed in 10.0.0~dfsg-11+deb12u7Fixed in 10.05.0~dfsg-1 - Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 9.51 - Upgrade
Upgrade
Artifex Software GhostScriptto a version that resolves this vulnerability.Fixed in 9.51 - Compensating control
If immediate upgrade is not possible, mitigate denial-of-service impact by restricting exposure so untrusted users cannot submit crafted PDFs to the GhostScript service (e.g., isolate/limit the rendering service and limit network/API access).
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-16295.
What is the severity of CVE-2020-16295?
The severity of CVE-2020-16295 is medium with a severity value of 5.5.
How does CVE-2020-16295 affect Artifex Software GhostScript?
CVE-2020-16295 allows a remote attacker to cause a denial of service via a crafted PDF file in Artifex Software GhostScript versions before v9.51.
How do I fix CVE-2020-16295 in Artifex Software GhostScript?
To fix CVE-2020-16295, update Artifex Software GhostScript to version 9.51 or later.
Where can I find more information about CVE-2020-16295?
You can find more information about CVE-2020-16295 on the following references: [Git Commit](http://git.ghostscript.com/?p=ghostpdl.git;h=2c2dc335c212750e0fb8ae157063bc06cafa8d3e), [Bugzilla](https://bugs.ghostscript.com/show_bug.cgi?id=701796), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1870180).