CVE-2020-17538: Buffer Overflow
A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Other sources
A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 9.53.3~dfsg-7+deb11u7Fixed in 9.53.3~dfsg-7+deb11u11Fixed in 10.0.0~dfsg-11+deb12u8Fixed in 10.05.1~dfsg-1+deb13u1Fixed in 10.07.0~dfsg-2 - Upgrade
Upgrade
redhat/ghostscriptto a version that resolves this vulnerability.Fixed in 9.51 - Upgrade
Upgrade
Artifex Software GhostScriptto a version that resolves this vulnerability.Fixed in v9.51Patch 701792 - Compensating control
Until upgraded, mitigate exposure by limiting how GhostScript processes untrusted/externally supplied PDF files (e.g., restrict PDF submission sources and avoid processing attacker-controlled PDFs).
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-17538.
What is the title of this vulnerability?
The title of this vulnerability is 'A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript v9.50.'
What is the severity level of CVE-2020-17538?
CVE-2020-17538 has a severity level of medium, with a severity value of 5.5.
How does CVE-2020-17538 affect Artifex Software GhostScript?
CVE-2020-17538 allows a remote attacker to cause a denial of service via a crafted PDF file in Artifex Software GhostScript v9.50.
How can I fix CVE-2020-17538 in Artifex Software GhostScript?
To fix CVE-2020-17538 in Artifex Software GhostScript, update to version 9.51 or later.