Medium severity5.5NVD Advisory· Published Apr 3, 2017· Updated May 13, 2026
CVE-2016-10220
CVE-2016-10220
Description
The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.
Affected products
1- cpe:2.3:a:artifex:ghostscript:9.20:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- bugs.ghostscript.com/show_bug.cginvdExploitIssue TrackingPatch
- www.ghostscript.com/cgi-bin/findgit.cginvdIssue TrackingVendor Advisory
- www.debian.org/security/2017/dsa-3838nvd
- security.gentoo.org/glsa/201708-06nvd
News mentions
0No linked articles in our index yet.