← Back to browse · API

CVE-2017-8291

Severity
HIGH
CVSS
7.8
EPSS
0.9614
Risk score
58.65
CISA KEV
Yes
PoC
No
Published
2017-04-27
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2017-17253, GHSA-RH88-CWV2-GJXM
Products
Artifex:Ghostscript, n/a:n/a n/a
Sources
cisa.gov CVE-2017-8291
euvd EUVD-2017-17253

Description

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.

References