CVE-2016-7977

MEDIUM

Ghostscript < 9.20 - Arbitrary File Read via .libfile Operator

Title source: llm
STIX 2.1

Description

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

References (11)

Core 11
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3691
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95334
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0013.html
Mailing List, Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/09/29/28
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0014.html
Issue Tracking, Patch x_refsource_confirm
https://bugs.ghostscript.com/show_bug.cgi?id=697169
Mailing List, Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/10/05/15
Release Notes x_refsource_confirm
https://ghostscript.com/doc/9.21/History9.htm
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201702-31

Scores

CVSS v3 5.5
EPSS 0.0138
EPSS Percentile 80.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
artifex/ghostscript < 9.20
Published May 23, 2017
Tracked Since Feb 18, 2026