Denial of Service Vulnerability in GhostXPS by Artifex
CVE-2017-9726

7.8HIGH

Key Information:

Vendor

Artifex

Vendor
CVE Published:
26 July 2017

What is CVE-2017-9726?

The Ins_MDRP function in the base/ttinterp.c file of Artifex Ghostscript GhostXPS version 9.21 is susceptible to a denial of service. Attackers can exploit this vulnerability by crafting a malicious document, resulting in a heap-based buffer over-read and potentially causing the application to crash. This type of vulnerability may also lead to additional unspecified impacts, highlighting the importance of applying necessary security updates to prevent exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.