CVE-2017-8291 - log back

CVE-2017-8291 created at 25 Sep 2019 19:31:40
Severity
+ High
Remote
+ Remote
Type
+ Arbitrary command execution
Description
+ It was found that ghostscript did not properly validate the parameters passed to the .rsdparams and .eqproc functions. During its execution, a specially crafted PostScript document could execute code via a "/OutputFile (%pipe%" substring in the context of the ghostscript process, bypassing the -dSAFER protection.
References
+ https://bugs.ghostscript.com/show_bug.cgi?id=697808
Notes