CVE-2016-7979

critical
Published 2017-05-23 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-7979

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-7979.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugs.ghostscript.com/show_bug.cgi?id=697190

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2016/10/05/15

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed9.19~dfsg-3.1
debian debianbullseyefixed9.19~dfsg-3.1
debian debianforkyfixed9.19~dfsg-3.1
debian debiansidfixed9.19~dfsg-3.1
debian debiantrixiefixed9.19~dfsg-3.1

Application impact

VendorProductVersionsFixed
artifexghostscript{"endIncluding":"9.20"}

References

CWEs

CWE-704

Verify integrity in audit chain (admin only). AS-IS.