peter bassill · operator
$ cve CVE-2017-8291 JSON

CVE-2017-8291 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 97% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-14.

Description

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS96.97% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-843
On CISA KEVyes — remediate by 2022-06-14
Public exploityes
Published2017-04-27
Last modified2026-06-17

CISA KEV

NameArtifex Ghostscript Type Confusion Vulnerability
Added2022-05-24
Due2022-06-14
Vendor / productArtifex / Ghostscript
Ransomware usenone reported

Affected (8)

VendorProduct
artifexghostscript
debiandebian linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD