RHSA-2021:1852MediumCVSS 7.8

Red Hat Security Advisory: ghostscript security, bug fix, and enhancement update

Published
May 18, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (26)

📋 Description

CVE-2020-14373 — ghostscript: use-after-free vulnerability in igc_reloc_struct_ptr() could result in DoS CVE-2020-16287 — ghostscript: buffer overflow in lprn_is_black() in contrib/lips4/gdevlprn.c could result in a DoS CVE-2020-16288 — ghostscript: buffer overflow in pj_common_print_page() in devices/gdevpjet.c could result in a DoS CVE-2020-16289 — ghostscript: buffer overflow in cif_print_page() in devices/gdevcif.c could result in a DoS CVE-2020-16290 — ghostscript: buffer overflow in jetp3852_print_page() in devices/gdev3852.c could result in a DoS CVE-2020-16291 — ghostscript: buffer overflow in contrib/gdevdj9.c could result in a DoS CVE-2020-16292 — ghostscript: buffer overflow in mj_raster_cmd() in contrib/japanese/gdevmjc.c could result in a DoS CVE-2020-16293 — ghostscript: NULL pointer dereference in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c could result in a DoS CVE-2020-16294 — ghostscript: buffer overflow in epsc_print_page() in devices/gdevepsc.c could result in a DoS CVE-2020-16295 — ghostscript: NULL pointer dereference in clj_media_size() in devices/gdevclj.c could result in a DoS CVE-2020-16296 — ghostscript: buffer overflow in GetNumWrongData() in contrib/lips4/gdevlips.c could result in a DoS CVE-2020-16297 — ghostscript: buffer overflow in FloydSteinbergDitheringC() in contrib/gdevbjca.c could result in a DoS CVE-2020-16298 — ghostscript: buffer overflow in mj_color_correct() in contrib/japanese/gdevmjc.c could result in a DoS CVE-2020-16299 — ghostscript: division by zero in bj10v_print_page() in contrib/japanese/gdev10v.c could result in a DoS CVE-2020-16300 — ghostscript: buffer overflow in tiff12_print_page() in devices/gdevtfnx.c could result in a DoS CVE-2020-16301 — ghostscript: buffer overflow in okiibm_print_page1() in devices/gdevokii.c could result in a DoS CVE-2020-16302 — ghostscript: buffer overflow in jetp3852_print_page() in devices/gdev3852.c could result in a privilege escalation CVE-2020-16303 — ghostscript: use-after-free in xps_finish_image_path() in devices/vector/gdevxps.c could result in a privilege escalation CVE-2020-16304 — ghostscript: buffer overflow in image_render_color_thresh() in base/gxicolor.c could result in a DoS CVE-2020-16305 — ghostscript: buffer overflow in pcx_write_rle() in contrib/japanese/gdev10v.c could result in a DoS CVE-2020-16306 — ghostscript: NULL pointer dereference in devices/gdevtsep.c could result in a DoS CVE-2020-16307 — ghostscript: NULL pointer dereference in devices/vector/gdevtxtw.c and psi/zbfont.c could result in a DoS CVE-2020-16308 — ghostscript: buffer overflow in p_print_image() in devices/gdevcdj.c could result in a DoS CVE-2020-16309 — ghostscript: buffer overflow in lxm5700m_print_page() in devices/gdevlxm.c could result in a DoS CVE-2020-16310 — ghostscript: division by zero in dot24_print_page() in devices/gdevdm24.c could result in a DoS CVE-2020-17538 — ghostscript: buffer overflow in GetNumSameData() in contrib/lips4/gdevlips.c could result in a DoS

🎯 Affected products84

  • Red Hat CodeReady Linux Builder (v. 8)
  • Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-0:9.27-1.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-0:9.27-1.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-0:9.27-1.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-0:9.27-1.el8.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-0:9.27-1.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.i686 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.s390x as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debuginfo-0:9.27-1.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.i686 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.s390x as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-debugsource-0:9.27-1.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • ghostscript-doc-0:9.27-1.el8.noarch as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-gtk-debuginfo-0:9.27-1.el8.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • ghostscript-gtk-debuginfo-0:9.27-1.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +54 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (32)