Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 9 | RedHat | ghostscript-0:9.54.0-17.el9_4 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | ghostscript-0:9.54.0-12.el9_2.2 | * |
Ghostscript | Ubuntu | devel | * |
Ghostscript | Ubuntu | esm-infra/bionic | * |
Ghostscript | Ubuntu | esm-infra/xenial | * |
Ghostscript | Ubuntu | focal | * |
Ghostscript | Ubuntu | jammy | * |
Ghostscript | Ubuntu | mantic | * |
Ghostscript | Ubuntu | noble | * |
Ghostscript | Ubuntu | oracular | * |
Ghostscript | Ubuntu | upstream | * |