CVE Vulnerabilities

CVE-2023-43115

Published: Sep 18, 2023 | Modified: Feb 22, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).

Affected Software

Name Vendor Start Version End Version
Ghostscript Artifex * 10.01.2 (including)
Red Hat Enterprise Linux 9 RedHat ghostscript-0:9.54.0-11.el9_2 *
Red Hat Enterprise Linux 9 RedHat ghostscript-0:9.54.0-14.el9_3 *
Red Hat Enterprise Linux 9.0 Extended Update Support RedHat ghostscript-0:9.54.0-7.el9_0.2 *
Ghostscript Ubuntu bionic *
Ghostscript Ubuntu devel *
Ghostscript Ubuntu esm-infra/bionic *
Ghostscript Ubuntu esm-infra/xenial *
Ghostscript Ubuntu focal *
Ghostscript Ubuntu jammy *
Ghostscript Ubuntu lunar *
Ghostscript Ubuntu mantic *
Ghostscript Ubuntu trusty *
Ghostscript Ubuntu upstream *
Ghostscript Ubuntu xenial *

References