CVE-2016-7977

MEDIUM

Artifex Ghostscript < 9.20 - Information Disclosure

Title source: rule

Description

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

Scores

CVSS v3 5.5
EPSS 0.0138
EPSS Percentile 80.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
artifex/ghostscript < 9.20
n/a/n/a
Published May 23, 2017
Tracked Since Feb 18, 2026