CVE-2020-16306: Null Pointer Dereference
A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 0:9.27-1.el8 - Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 9.53.3~dfsg-7+deb11u7Fixed in 9.53.3~dfsg-7+deb11u11Fixed in 10.0.0~dfsg-11+deb12u8Fixed in 10.05.1~dfsg-1+deb13u1Fixed in 10.06.0~dfsg-3Fixed in 10.07.0~dfsg-2 - Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 9.51 - Upgrade
Upgrade
Artifex Software GhostScriptto a version that resolves this vulnerability.Fixed in 9.51
Event History
Frequently Asked Questions
What is CVE-2020-16306?
CVE-2020-16306 is a null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50.
How does CVE-2020-16306 impact the system?
CVE-2020-16306 allows a remote attacker to cause a denial of service via a crafted postscript file.
What is the severity of CVE-2020-16306?
CVE-2020-16306 has a severity level of medium (5.5).
Which version of GhostScript fixes CVE-2020-16306?
CVE-2020-16306 is fixed in GhostScript v9.51.
Where can I find more information about CVE-2020-16306?
You can find more information about CVE-2020-16306 at the following references: [Reference 1](http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=aadb53eb834b3def3ef68d78865ff87a68901804), [Reference 2](https://bugs.ghostscript.com/show_bug.cgi?id=701821), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1870166).