A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Details
- CVSS 3.1 Base Score: 9.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ghostscript | Mar 26, 2024 | Feb 16, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 16, 2022 |
| Debian | — | Upgrade ghostscript | Nov 4, 2022 | Feb 16, 2022 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Nov 23, 2022 | Feb 16, 2022 |
| Ghostscript | — | Upgrade to Ghostscript version 9.55 | Mar 22, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade ghostscriptUpgrade ghostscript-help | Jun 7, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade ghostscript-helpUpgrade ghostscript | Jun 16, 2022 | Feb 16, 2022 |
| Oracle Solaris | — | Upgrade desktop/pdf-viewer/gsx to version 9.54.0-11.4.38.0.1.101.3 on Solaris 11.4Upgrade image/ghostscript to version 9.54.0-11.4.38.0.1.101.3 on Solaris 11.4 | Nov 17, 2021 | Nov 17, 2021 |
| Suse | — | Upgrade ghostscriptUpgrade ghostscript-x11Upgrade ghostscript-miniUpgrade ghostscript-mini-develUpgrade ghostscript-develUpgrade libspectre1Upgrade libspectre-devel | Sep 16, 2021 | Sep 10, 2021 |
| Ubuntu | — | Upgrade libgs9Upgrade ghostscript | Sep 11, 2021 | Sep 10, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub