A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-ghostscript | Oct 1, 2024 | Jul 28, 2020 | |
| Debian | debian-upgrade-ghostscript | Jul 30, 2024 | Jul 28, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-app-text-ghostscript-gpl | Aug 31, 2020 | Jul 28, 2020 | |
| Ghostscript | ghostscript-upgrade-latest | Aug 7, 2020 | Jul 28, 2020 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-desktop-pdf-viewer-gsx-9-53-3-11-4-30-0-1-88-0oracle-solaris-11-4-upgrade-image-ghostscript-9-53-3-11-4-30-0-1-88-0 | Feb 17, 2021 | Jul 28, 2020 | |
| Suse | — | suse-upgrade-ghostscriptsuse-upgrade-ghostscript-develsuse-upgrade-ghostscript-minisuse-upgrade-ghostscript-mini-develsuse-upgrade-ghostscript-x11 | Aug 1, 2020 | Jul 28, 2020 |
| Ubuntu | ubuntu-upgrade-ghostscriptubuntu-upgrade-libgs9 | Aug 5, 2020 | Jul 28, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub