CVE-2017-8291
KEV PoC ×2massGhostscript Type Confusion Flaw Enables Command Execution via Crafted EPS Files
CISA: Artifex Ghostscript Type Confusion Vulnerability
Ghostscript versions through 2017-04-26 contain a type confusion flaw (CWE-843) in the .rsdparams routine that also permits bypass of the -dSAFER security sandbox. The flaw is triggered when the gs program processes a crafted .eps (PostScript) document containing a "/OutputFile (%pipe%" substring, which causes Ghostscript to execute embedded operating system commands. An attacker gains command execution with the privileges of the gs process, which commonly runs in document-conversion pipelines, print servers, and image-processing tools such as ImageMagick. Users of upstream Ghostscript and distributions that ship it, notably Debian and Red Hat Enterprise Linux desktop, server, and workstation variants, are affected. The flaw was exploited in the wild in April 2017, was added to the CISA Known Exploited Vulnerabilities catalog on 2022-05-24, and carries a 97% EPSS probability of exploitation.
What to do: Apply the Ghostscript fixes released after 2017-04-26 per your distribution's security advisories (Debian, Red Hat) and upstream Artifex updates, as required by CISA's KEV listing. As interim mitigation, avoid processing untrusted EPS/PostScript files with gs, including indirect processing via ImageMagick/convert pipelines and print servers, since the %pipe% OutputFile trick executes shell commands. Inventory systems that run Ghostscript for server-side document or image conversion, as those face the greatest exposure.
| artifex ghostscript | through 2017-04-26 |
| debian linux | releases shipping Ghostscript through 2017-04-26 (consult Debian security advisories) |
| redhat enterprise linux desktop | releases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories) |
| redhat enterprise linux eus | releases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories) |
| redhat enterprise linux server | releases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories) |
| redhat enterprise linux server aus | releases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories) |
| redhat enterprise linux server tus | releases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories) |
| redhat enterprise linux workstation | releases shipping Ghostscript through 2017-04-26 (consult Red Hat security advisories) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.
- Affected
- Artifex Ghostscript
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown