USN-6364-1: Ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled certain PDF files. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-21710) It was discovered that Ghostscript incorrectly handled certain PDF files. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2020-21890)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for these Ghostscript vulnerabilities?
The vulnerability ID for these Ghostscript vulnerabilities is CVE-2020-21710.
What is the severity of CVE-2020-21710?
The severity of CVE-2020-21710 is not specified in the information provided.
How can an attacker exploit CVE-2020-21710?
An attacker could exploit CVE-2020-21710 by using a specially crafted PDF file to cause a denial of service.
Which software versions are affected by these vulnerabilities?
The affected software versions are Ghostscript 9.50~dfsg-5ubuntu4.10, libgs9 9.50~dfsg-5ubuntu4.10, Ghostscript 9.26~dfsg+0-0ubuntu0.18.04.18+esm2, libgs9 9.26~dfsg+0-0ubuntu0.18.04.18+esm2, Ghostscript 9.26~dfsg+0-0ubuntu0.16.04.14+esm7, and libgs9 9.26~dfsg+0-0ubuntu0.16.04.14+esm7.
How do I fix the Ghostscript vulnerabilities?
To fix the Ghostscript vulnerabilities, it is recommended to update to the latest version of the affected software packages as specified in the provided references.