CVE-2017-8291

artifex ghostscript, debian linux, redhat enterprise linux desktop

Published 27 Apr 2017 · updated 17 Jun 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 24 May 2022, with a remediation deadline of 14 Jun 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.

References