CVE-2017-7975 describes an integer overflow vulnerability in Artifex jbig2dec 0.13, specifically within the jbig2_build_huffman_table function, which is used by Ghostscript. This flaw allows out-of-bounds writes when processing a specially crafted JBIG2 file, potentially leading to a denial of service or arbitrary code execution. Rated with a CVSS score of 7.8 (High), it requires local access and user interaction (e.g., opening a malicious file) for exploitation. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage, suggesting a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.13CPE matchmatch criteria | cpe:2.3:a:artifex:jbig2dec:0.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.