cbcvebase.
CVE-2021-3781
published 2022-02-16

CVE-2021-3781: A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This…

PriorityP277critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
83.91%
99.7th percentile
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Affected

11 ranges
VendorProductVersion rangeFixed in
artifexghostscript
artifexghostscript
artifexghostscript
artifexghostscript
artifexghostscript
artifexghostscript>= 0 < 9.53.3~dfsg-7+deb11u19.53.3~dfsg-7+deb11u1
artifexghostscript>= 0 < 9.53.3~dfsg-89.53.3~dfsg-8
artifexghostscript>= 0 < 9.53.3~dfsg-89.53.3~dfsg-8
artifexghostscript>= 0 < 9.53.3~dfsg-89.53.3~dfsg-8
debianghostscript< ghostscript 9.53.3~dfsg-8 (bookworm)ghostscript 9.53.3~dfsg-8 (bookworm)
fedoraprojectfedora

Detection & IOCsextracted from sources · hover to see the quote

  • Look for use of the '%pipe%' construct in PostScript/Ghostscript documents, which is the injection vector used to escape the -dSAFER sandbox
  • Detect Ghostscript processing of documents containing specially crafted pipe commands that bypass the -dSAFER sandbox restriction
  • Flag Ghostscript invocations where arbitrary command execution occurs despite -dSAFER being enabled, as the sandbox can be trivially bypassed via pipe injection
  • ·This flaw only affects Ghostscript versions 9.50 and later; versions prior to 9.50 are not vulnerable
  • ·The -dSAFER sandbox option does NOT provide protection against this vulnerability; do not rely on it as a mitigation
  • ·Exploitation can be triggered by automated systems processing files without user interaction, widening the attack surface

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.9CRITICAL
vendor_debian9.9CRITICAL
vendor_redhat9.9CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.