vendor:
Ghostscript
by:
Atlassian Security Team and hdm
N/A
CVSS
N/A
Type confusion vulnerability
CWE
Product Name: Ghostscript
Affected Version From: 9.21 and earlier
Affected Version To:
Patch Exists: NO
Related CWE: CVE 2017-8291
CPE:
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ghostscript-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-8291/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-8291/
Platforms Tested: unix
Apr 27 2017
Ghostscript Type Confusion Arbitrary Command Execution
This module exploits a type confusion vulnerability in Ghostscript that can be exploited to obtain arbitrary command execution. This vulnerability affects Ghostscript version 9.21 and earlier and can be exploited through libraries such as ImageMagick and Pillow.