CVE-2020-15900
published 2020-07-28CVE-2020-15900: A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.19%
91.5th percentile
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | >= 0 < 9.52.1~dfsg-1 | 9.52.1~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.52.1~dfsg-1 | 9.52.1~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.52.1~dfsg-1 | 9.52.1~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.52.1~dfsg-1 | 9.52.1~dfsg-1 |
| canonical | ubuntu_linux | — | — |
| debian | ghostscript | < ghostscript 9.52.1~dfsg-1 (bookworm) | ghostscript 9.52.1~dfsg-1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mwgq-j58h-pv6j: A memory corruption issue was found in Artifex Ghostscript 9
ghsa_unreviewed·2022-05-24
CVE-2020-15900 [HIGH] CWE-119 GHSA-mwgq-j58h-pv6j: A memory corruption issue was found in Artifex Ghostscript 9
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
OSV
CVE-2020-15900: A memory corruption issue was found in Artifex Ghostscript 9
osv·2020-07-28·CVSS 9.8
CVE-2020-15900 [CRITICAL] CVE-2020-15900: A memory corruption issue was found in Artifex Ghostscript 9
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2020-08-03
CVE-2020-15900 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash, access files, or run programs if it
opened a specially crafted file.
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
access arbitrary files, execute arbitrary code,
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout)
vendor_redhat·2020-07-27·CVSS 9.8
CVE-2020-15900 [CRITICAL] CWE-131 ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout)
ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout)
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
Ghostscript's rsearch procedure was vulnerable to an integer underflow, leading to a miscalculation of the size of a buffer, which then can be used to access arbitrary memory. As a result, a specially crafted postscript file could use this flaw to disable the sandbox, which allows arbitrary reads and writes on the file system and execute commands.
Package: ghostscript
Debian
CVE-2020-15900: ghostscript - A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of...
vendor_debian·2020·CVSS 9.8
CVE-2020-15900 [CRITICAL] CVE-2020-15900: ghostscript - A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of...
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
Scope: local
bookworm: resolved (fixed in 9.52.1~dfsg-1)
bullseye: resolved (fixed in 9.52.1~dfsg-1)
forky: resolved (fixed in 9.52.1~dfsg-1)
sid: resolved (fixed in 9.52.1~dfsg-1)
trixie: resolved (fixed in 9.52.1~dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15900 ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout) [fedora-all]
bugzilla·2020-07-30·CVSS 9.8
CVE-2020-15900 [CRITICAL] CVE-2020-15900 ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout) [fedora-all]
CVE-2020-15900 ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2020-15900 ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout)
bugzilla·2020-07-22·CVSS 9.8
CVE-2020-15900 [CRITICAL] CVE-2020-15900 ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout)
CVE-2020-15900 ghostscript: Memory Corruption in Ghostscript 9.52 (SAFER Sandbox Breakout)
The vulnerability occurs in the "rsearch" Postscript function, as
implemented in:
https://github.com/ArtifexSoftware/ghostpdl/blob/master/psi/zstring.c#L109
When conducting a reverse search for an empty string in an empty string
as follows:
```
%!PS
() dup rsearch
```
The length of the pre-match result is decremented from zero, resulting in
a string reference of length 2**32-1. This may subsequently be used to read
and write up to 4GB of memory.
Discussion:
The vulnerability affects ghostcript versions >= 9.50, and has been introduced by upstream commit 7ecbfda92b4c8dbf6f6c2bf8fc82020a29219eff
---
Acknowledgments:
Name: Chris Liddell (Artifex)
Upstream: Timothy Goddard (Insomnia Security)
http://git.ghostscript.com/?p=ghostpdl.git%3Ba=loghttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00006.htmlhttps://artifex.com/security-advisories/CVE-2020-15900https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=5d499272b95a6b890a1397e11d20937de000d31bhttps://github.com/ArtifexSoftware/ghostpdl/commit/5d499272b95a6b890a1397e11d20937de000d31bhttps://github.com/ArtifexSoftware/ghostpdl/commits/master/psi/zstring.chttps://security.gentoo.org/glsa/202008-20https://usn.ubuntu.com/4445-1/http://git.ghostscript.com/?p=ghostpdl.git%3Ba=loghttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00006.htmlhttps://artifex.com/security-advisories/CVE-2020-15900https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=5d499272b95a6b890a1397e11d20937de000d31bhttps://github.com/ArtifexSoftware/ghostpdl/commit/5d499272b95a6b890a1397e11d20937de000d31bhttps://github.com/ArtifexSoftware/ghostpdl/commits/master/psi/zstring.chttps://security.gentoo.org/glsa/202008-20https://usn.ubuntu.com/4445-1/
2020-07-28
Published