REDHAT-BUG-1434353: Low severity artifex ghostscript vulnerability
A null pointer vulnerability was found in memgetbitsrectangle() when trying to read from unallocated memory.
Upstream bug:
https://bugs.ghostscript.com/showbug.cgi?id=697676
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;h=309eca4e0a31ea70dcc844812691439312dad091
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1434353?
The severity of REDHAT-BUG-1434353 is considered medium due to its potential to cause null pointer dereference.
How do I fix REDHAT-BUG-1434353?
To fix REDHAT-BUG-1434353, apply the upstream patch provided in the Ghostscript repository.
What software is affected by REDHAT-BUG-1434353?
REDHAT-BUG-1434353 affects Ghostscript software.
Is there an upstream bug report for REDHAT-BUG-1434353?
Yes, there is an upstream bug report for REDHAT-BUG-1434353 which can be found detailed on the Ghostscript bug tracking page.
What causes the vulnerability in REDHAT-BUG-1434353?
The vulnerability in REDHAT-BUG-1434353 is caused by a null pointer dereference when reading from unallocated memory.