Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initializedscparser.
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
If you call .sethalftone5 with an empty operand stack, ghostscript crashes. This flaw could be exploitable
Upstream bug : - Bug 697203 - NULL dereference in .sethalftone5 http://bugs.ghostscript.com/showbug.cgi?id=697203
Upstream patch : - Bug 697203: check for sufficient params in .sethalftone5 http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=f5c7555c303
Reference : http://seclists.org/oss-sec/2016/q4/98
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.
The pdf14poptransparencygroup function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
The gsmakewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.
The pdf14open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file that is mishandled in the color management module.
Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which can allow remote attackers to determine the existence and size of arbitrary files.
Upstream bug:
https://bugs.ghostscript.com/showbug.cgi?id=697193
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=b60d50b7567369ad856cebe1efb6cd7dd2284219