PublicDateAtUSN: 2016-10-06 Candidate: CVE-2016-7978 PublicDate: 2017-05-23 04:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7978 http://www.openwall.com/lists/oss-security/2016/10/05/7 https://ubuntu.com/security/notices/USN-3148-1 Description: Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice. Ubuntu-Description: Notes: sbeattie> reproducer in ghostscript bug report Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=839845 http://bugs.ghostscript.com/show_bug.cgi?id=697179 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_ghostscript: upstream: http://git.ghostscript.com/?p=user/chrisl/ghostpdl.git;h=d5ad1e0298e1c193087c824eb4f79628b182e28b upstream_ghostscript: needs-triage precise_ghostscript: released (9.05~dfsg-0ubuntu4.4) trusty_ghostscript: released (9.10~dfsg-0ubuntu10.5) trusty/esm_ghostscript: DNE (trusty was released [9.10~dfsg-0ubuntu10.5]) vivid/stable-phone-overlay_ghostscript: DNE vivid/ubuntu-core_ghostscript: DNE xenial_ghostscript: released (9.18~dfsg~0-0ubuntu2.2) esm-infra/xenial_ghostscript: released (9.18~dfsg~0-0ubuntu2.2) yakkety_ghostscript: released (9.19~dfsg+1-0ubuntu6.2) devel_ghostscript: released (9.19~dfsg+1-0ubuntu7.1)