CVE-2016-7976

Related Vulnerabilities: CVE-2016-7976  

The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

The MITRE CVE dictionary describes this issue as:

The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

Find out more about CVE-2016-7976 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Impact Low
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat OpenShift Enterprise 2 ghostscript Not affected
Red Hat Enterprise Linux 7 ghostscript Not affected
Red Hat Enterprise Linux 6 ghostscript Not affected
Red Hat Enterprise Linux 5 ghostscript Not affected