#CVE-2017-8291

Vulnerability/Target

2018-01-16 • North Korea Targeted South Korean Cryptocurrency Users and Exchange in Late 2017 Campaign

Artifex Ghostscript through April 26, 2017 is vulnerable to an .rsdparams type-confusion issue that can bypass -dSAFER and enable remote command execution. Exploitation uses a crafted EPS document supplied to the gs program with a "/OutputFile (%pipe%" substring, and the issue was exploited in the wild in April 2017.

https://www.cve.org/CVERecord?id=CVE-2017-8291

Tagged Reports

« Back