Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-04-27T01:41:00

Updated: 2018-01-04T19:57:01

Reserved: 2017-04-26T00:00:00


Link: CVE-2017-8291

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-04-27T01:59:02.057

Modified: 2023-11-07T02:50:23.893


Link: CVE-2017-8291

JSON object: View

cve-icon Redhat Information

No data.

CWE