
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-16287 is a buffer overflow vulnerability discovered in Ghostscript, an interpreter for PostScript and PDF documents. The vulnerability was identified in the lprn_is_black() function located in contrib/lips4/gdevlprn.c. This security issue was reported on October 26, 2019, and was fixed in subsequent updates (Ghostscript Bug).
The vulnerability is a heap-based buffer overflow that occurs in the lprn_is_black() function at line 338 of contrib/lips4/gdevlprn.c. The issue manifests when processing certain document files, specifically when using the lips2p output device. The bug was discovered through testing with AddressSanitizer, which detected a heap-buffer-overflow READ operation (Ghostscript Bug).
If exploited, this vulnerability could result in a denial of service (DoS) condition when processing specially crafted PS/EPS/PDF files. The buffer overflow could potentially lead to system crashes and service disruption (Ubuntu Notice, Debian Notice).
The vulnerability can be triggered by processing a specially crafted file using the Ghostscript interpreter with the lips2p device. An attacker would need to trick a user or automated system into processing a malicious document to exploit this vulnerability (Ubuntu Notice).
The vulnerability was fixed in Ghostscript version 9.27 and later releases. Users are recommended to upgrade their Ghostscript installations to patched versions. For specific distributions: Ubuntu users should update to versions 9.50~dfsg-5ubuntu4.2 (20.04), 9.26~dfsg+0-0ubuntu0.18.04.13 (18.04), or 9.26~dfsg+0-0ubuntu0.16.04.13 (16.04). Debian users should upgrade to version 9.27~dfsg-2+deb10u4 for the stable distribution (Ubuntu Notice, Debian Notice).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."