Intrusion Prevention

Ghostscript.Type.Confusion.Arbitrary.Command.Execution

Description

This indicates an attack attempt to exploit a Command Execution vulnerability in Ghostscript.
The vulnerability is due to improper validation of user supplied inputs when handling a crafted EPS file. A remote attacker may be able to exploit this to execute arbitrary command within the context of the process, via a crafted EPS file.

Affected Products

Ghostscript version 9.21 and prior version

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrades or patches from the vendor.

CVE References

CVE-2017-8291

Other References

697808