logo

CVE-2017-8291 - Artifex Ghostscript Type Confusion Vulnerability

Project:Artifex

Product:Ghostscript

Date Added:2022-05-24Due Date:2022-06-14

Vulnerability Name

Artifex Ghostscript Type Confusion Vulnerability

Description

Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2017-8291