CVE-2020-16297: Buffer Overflow
A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Other sources
A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 9.53.3~dfsg-7+deb11u7Fixed in 9.53.3~dfsg-7+deb11u10Fixed in 10.0.0~dfsg-11+deb12u6Fixed in 10.0.0~dfsg-11+deb12u7Fixed in 10.05.0~dfsg-1 - Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 9.51 - Upgrade
Upgrade
Artifex Software GhostScriptto a version that resolves this vulnerability.Fixed in v9.51
Event History
Frequently Asked Questions
What is the vulnerability ID of this buffer overflow vulnerability in GhostScript?
The vulnerability ID is CVE-2020-16297.
What is the affected software?
The affected software is GhostScript.
What is the severity rating of CVE-2020-16297?
The severity rating of CVE-2020-16297 is medium.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by sending a crafted PDF file.
How can I fix this vulnerability in GhostScript?
You can fix this vulnerability by updating to GhostScript version 9.51.