REDHAT-BUG-1383940: Medium severity Ghostscript Ghostscript vulnerability
If you call .sethalftone5 with an empty operand stack, ghostscript crashes. This flaw could be exploitable
Upstream bug : - Bug 697203 - NULL dereference in .sethalftone5 http://bugs.ghostscript.com/showbug.cgi?id=697203
Upstream patch : - Bug 697203: check for sufficient params in .sethalftone5 http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=f5c7555c303
Reference : http://seclists.org/oss-sec/2016/q4/98
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1383940?
The severity of REDHAT-BUG-1383940 is classified as a crash vulnerability.
How do I fix REDHAT-BUG-1383940?
To fix REDHAT-BUG-1383940, ensure that you do not call .sethalftone5 with an empty operand stack.
What is the impact of exploiting REDHAT-BUG-1383940?
Exploiting REDHAT-BUG-1383940 can lead to a crash of the Ghostscript application.
Which software versions are affected by REDHAT-BUG-1383940?
REDHAT-BUG-1383940 affects certain versions of Ghostscript.
Is there a workaround for REDHAT-BUG-1383940?
A possible workaround for REDHAT-BUG-1383940 is to validate the operand stack before executing the command.