Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-16304
Ghostscript vulnerability analysis and mitigation

Overview

A buffer overflow vulnerability was discovered in the image_render_color_thresh() function in base/gxicolor.c of Artifex Software GhostScript versions 9.18 to 9.50. The vulnerability was identified in August 2020 and affects the PostScript and PDF interpreter's image rendering functionality (Debian Tracker, Ubuntu Security).

Technical details

The vulnerability exists in the image rendering component of GhostScript, specifically in the image_render_color_thresh() function located in base/gxicolor.c. The issue occurs due to incorrect decrementing of position per-component rather than per-pixel in two locations, which can lead to a buffer overflow condition (Ghostscript Bug).

Impact

When exploited, this vulnerability could allow an attacker to cause a denial of service (DoS) condition or potentially escalate privileges via a crafted EPS file (Red Hat Portal, Ubuntu Security).

Exploitability

The vulnerability can be triggered by processing a specially crafted EPS file. A proof of concept exploit exists that requires specific version conditions to trigger the vulnerability (Debian Tracker).

Mitigation and workarounds

The vulnerability was fixed in GhostScript version 9.51 through commit 027c546e0dd11e0526f1780a7f3c2c66acffe209. Users are advised to upgrade to version 9.51 or later to address this security issue (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Ghostscript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-39919CRITICAL9.3
  • Ghostscript logoGhostscript
  • ghostscript
NoNoSep 15, 2026
CVE-2025-59800MEDIUM5.5
  • Ghostscript logoGhostscript
  • ghostscript-devel
NoYesSep 22, 2025
CVE-2025-59799MEDIUM5.5
  • Ghostscript logoGhostscript
  • ghostscript-tools-dvipdf
NoYesSep 22, 2025
CVE-2025-59801MEDIUM4.3
  • Ghostscript logoGhostscript
  • ghostscript-devel
NoYesSep 22, 2025
CVE-2026-6192LOW1.9
  • Ghostscript logoGhostscript
  • texmaker
NoYesApr 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management