PublicDateAtUSN: 2016-10-06 Candidate: CVE-2016-7976 PublicDate: 2017-08-07 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7976 http://www.openwall.com/lists/oss-security/2016/10/05/7 http://www.openwall.com/lists/oss-security/2016/09/30/8 https://ubuntu.com/security/notices/USN-3148-1 Description: The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams. Ubuntu-Description: Notes: sbeattie> reproducer in second oss-security post Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=839260 http://bugs.ghostscript.com/show_bug.cgi?id=697178 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_ghostscript: upstream: http://git.ghostscript.com/?p=user/chrisl/ghostpdl.git;a=commitdiff;h=71ac87493b1e445d6c07554d4246cf7d4f44875c upstream_ghostscript: needs-triage precise_ghostscript: released (9.05~dfsg-0ubuntu4.4) trusty_ghostscript: released (9.10~dfsg-0ubuntu10.5) trusty/esm_ghostscript: DNE (trusty was released [9.10~dfsg-0ubuntu10.5]) vivid/stable-phone-overlay_ghostscript: DNE vivid/ubuntu-core_ghostscript: DNE xenial_ghostscript: released (9.18~dfsg~0-0ubuntu2.2) esm-infra/xenial_ghostscript: released (9.18~dfsg~0-0ubuntu2.2) yakkety_ghostscript: released (9.19~dfsg+1-0ubuntu6.2) devel_ghostscript: released (9.19~dfsg+1-0ubuntu7.1)