Executive brief
Artifex Ghostscript is vulnerable to a type confusion via .rsdparams when processing a crafted .eps document. An attacker can bypass the -dSAFER restriction and execute arbitrary commands by using a specifically formatted OutputFile string.
Affected products
- Artifex Ghostscript up to 9.21
Timeline
- 2017-04-27: exploited: Exploited in the wild in April 2017.
- 2017-04-27: disclosed: Vulnerability reported in Ghostscript bug tracker.
- 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.