CVE-2021-3781
published 2022-02-16CVE-2021-3781: A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This…
PriorityP277critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
83.91%
99.7th percentile
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u1 | 9.53.3~dfsg-7+deb11u1 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-8 | 9.53.3~dfsg-8 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-8 | 9.53.3~dfsg-8 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-8 | 9.53.3~dfsg-8 |
| debian | ghostscript | < ghostscript 9.53.3~dfsg-8 (bookworm) | ghostscript 9.53.3~dfsg-8 (bookworm) |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for use of the '%pipe%' construct in PostScript/Ghostscript documents, which is the injection vector used to escape the -dSAFER sandbox ↗
- →Detect Ghostscript processing of documents containing specially crafted pipe commands that bypass the -dSAFER sandbox restriction ↗
- →Flag Ghostscript invocations where arbitrary command execution occurs despite -dSAFER being enabled, as the sandbox can be trivially bypassed via pipe injection ↗
- ·This flaw only affects Ghostscript versions 9.50 and later; versions prior to 9.50 are not vulnerable ↗
- ·The -dSAFER sandbox option does NOT provide protection against this vulnerability; do not rely on it as a mitigation ↗
- ·Exploitation can be triggered by automated systems processing files without user interaction, widening the attack surface ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.9CRITICAL
vendor_debian9.9CRITICAL
vendor_redhat9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gf7q-r6ff-xwg6: A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe comma
ghsa_unreviewed·2022-02-17
CVE-2021-3781 [CRITICAL] CWE-20 GHSA-gf7q-r6ff-xwg6: A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe comma
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
OSV
CVE-2021-3781: A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe comma
osv·2022-02-16·CVSS 9.9
CVE-2021-3781 [CRITICAL] CVE-2021-3781: A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe comma
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Red Hat
ghostscript: sandbox escape using '%pipe%'
vendor_redhat·2021-09-10·CVSS 9.9
CVE-2021-3781 [CRITICAL] CWE-78 ghostscript: sandbox escape using '%pipe%'
ghostscript: sandbox escape using '%pipe%'
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2021-09-10
CVE-2021-3781 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash, access files, or run programs if it
opened a specially crafted file.
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
access arbitrary files, execute arbitrary code, or cause a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-3781: ghostscript - A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in t...
vendor_debian·2021·CVSS 9.9
CVE-2021-3781 [CRITICAL] CVE-2021-3781: ghostscript - A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in t...
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Scope: local
bookworm: resolved (fixed in 9.53.3~dfsg-8)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u1)
forky: resolved (fixed in 9.53.3~dfsg-8)
sid: resolved (fixed in 9.53.3~dfsg-8)
trixie: resolved (fixed in 9.53.3~dfsg-8)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-16
Published