CVE record
CVE-2017-8291
Artifex Ghostscript Type Confusion Vulnerability
Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
high
CVSS 7.8 ยท CVSS_V3
Affected packages
0
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- Artifex
- Product
- Ghostscript
- Date added
- May 24, 2022
- CISA federal remediation due date
- Jun 14, 2022
- Required action
- Apply updates per vendor instructions.
- Known ransomware campaign use
- Unknown
- CWE
- CWE-704
OSV package mapping
Affected open-source packages
OSV did not return a package mapping in the five supported ecosystems. RequestGuard does not infer package names from the CISA vendor or product fields.