High severity7.8NVD Advisory· Published Apr 14, 2017· Updated May 13, 2026
CVE-2016-8602
CVE-2016-8602
Description
The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Postscript document that calls .sethalftone5 with an empty operand stack.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- www.openwall.com/lists/oss-security/2016/10/11/5nvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2016/10/11/7nvdMailing ListPatchThird Party Advisory
- bugs.ghostscript.com/show_bug.cginvdIssue TrackingPatch
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatch
- ghostscript.com/doc/9.21/History9.htmnvdPatchVendor Advisory
- www.securityfocus.com/bid/95311nvdThird Party AdvisoryVDB Entry
- git.ghostscript.comnvd
- rhn.redhat.com/errata/RHSA-2017-0013.htmlnvd
- rhn.redhat.com/errata/RHSA-2017-0014.htmlnvd
- www.debian.org/security/2016/dsa-3691nvd
- security.gentoo.org/glsa/201702-31nvd
News mentions
0No linked articles in our index yet.