ZeroHour

CVE-2017-8291

KEV PoC ×2mass

Ghostscript Type Confusion Flaw Enables Command Execution via Crafted EPS Files

CISA: Artifex Ghostscript Type Confusion Vulnerability

CVSS 3.1
7.8 high
EPSS
97%p100
Published
()
KEV added
AI analysis

Ghostscript versions through 2017-04-26 contain a type confusion flaw (CWE-843) in the .rsdparams routine that also permits bypass of the -dSAFER security sandbox. The flaw is triggered when the gs program processes a crafted .eps (PostScript) document containing a "/OutputFile (%pipe%" substring, which causes Ghostscript to execute embedded operating system commands. An attacker gains command execution with the privileges of the gs process, which commonly runs in document-conversion pipelines, print servers, and image-processing tools such as ImageMagick. Users of upstream Ghostscript and distributions that ship it, notably Debian and Red Hat Enterprise Linux desktop, server, and workstation variants, are affected. The flaw was exploited in the wild in April 2017, was added to the CISA Known Exploited Vulnerabilities catalog on 2022-05-24, and carries a 97% EPSS probability of exploitation.

What to do: Apply the Ghostscript fixes released after 2017-04-26 per your distribution's security advisories (Debian, Red Hat) and upstream Artifex updates, as required by CISA's KEV listing. As interim mitigation, avoid processing untrusted EPS/PostScript files with gs, including indirect processing via ImageMagick/convert pipelines and print servers, since the %pipe% OutputFile trick executes shell commands. Inventory systems that run Ghostscript for server-side document or image conversion, as those face the greatest exposure.

Affected
artifex ghostscriptthrough 2017-04-26
debian linuxreleases shipping Ghostscript through 2017-04-26 (consult Debian security advisories)
redhat enterprise linux desktopreleases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories)
redhat enterprise linux eusreleases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories)
redhat enterprise linux serverreleases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories)
redhat enterprise linux server ausreleases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories)
redhat enterprise linux server tusreleases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories)
redhat enterprise linux workstationreleases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories)
Estimated exposure
masstens of millions of installations (Ghostscript is a default component in most major Linux distributions) — Ghostscript is bundled by default across major Linux distributions and is invoked by print spoolers, ImageMagick/convert pipelines, and document converters, so the installed base is in the millions, though exploitation requires processing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.

CISA Known Exploited Vulnerability
Affected
Artifex Ghostscript
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
artifexdebianredhat
Products
ghostscript, debian linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news