
Cloud Vulnerability DB
A community-led vulnerabilities database
A buffer overflow vulnerability was discovered in the image_render_color_thresh() function in base/gxicolor.c of Artifex Software GhostScript versions 9.18 to 9.50. The vulnerability was identified in August 2020 and affects the PostScript and PDF interpreter's image rendering functionality (Debian Tracker, Ubuntu Security).
The vulnerability exists in the image rendering component of GhostScript, specifically in the image_render_color_thresh() function located in base/gxicolor.c. The issue occurs due to incorrect decrementing of position per-component rather than per-pixel in two locations, which can lead to a buffer overflow condition (Ghostscript Bug).
When exploited, this vulnerability could allow an attacker to cause a denial of service (DoS) condition or potentially escalate privileges via a crafted EPS file (Red Hat Portal, Ubuntu Security).
The vulnerability can be triggered by processing a specially crafted EPS file. A proof of concept exploit exists that requires specific version conditions to trigger the vulnerability (Debian Tracker).
The vulnerability was fixed in GhostScript version 9.51 through commit 027c546e0dd11e0526f1780a7f3c2c66acffe209. Users are advised to upgrade to version 9.51 or later to address this security issue (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."