CVE-2022-1350
published 2022-04-14CVE-2022-1350: A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.81%
52.8th percentile
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostpcl | — | — |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-3 | 10.0.0~dfsg-3 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-3 | 10.0.0~dfsg-3 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-3 | 10.0.0~dfsg-3 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-3 (bookworm) | ghostscript 10.0.0~dfsg-3 (bookworm) |
| github.com | coreos_ignition | >= 0 < 2.14.0 | 2.14.0 |
| github.com | coreos_ignition_v2 | >= 0 < 2.14.0 | 2.14.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
cisa10.0CRITICAL
vendor_redhat6.9MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ignition config accessible to unprivileged software on VMware
ghsa·2022-05-25
CVE-2022-1706 [MEDIUM] CWE-200 Ignition config accessible to unprivileged software on VMware
Ignition config accessible to unprivileged software on VMware
### Impact
Unprivileged software in VMware VMs, including software running in unprivileged containers, can retrieve an Ignition config stored in a hypervisor guestinfo variable or OVF environment. If the Ignition config contains secrets, this can result in the compromise of sensitive information.
### Patches
Ignition 2.14.0 and later [adds](https://github.com/coreos/ignition/pull/1350) a new systemd service, `ignition-delete-config.service`, that deletes the Ignition config from supported hypervisors (currently VMware and VirtualBox) during the first boot. This ensures that unprivileged software cannot retrieve the Ignition config from the hypervisor.
If you have external tooling that requires the Ignition config to remain ac
GHSA
GHSA-jpg4-pmwv-rq38: A vulnerability classified as problematic was found in Ghostscript 9
ghsa_unreviewed·2022-04-15
CVE-2022-1350 [HIGH] CWE-787 GHSA-jpg4-pmwv-rq38: A vulnerability classified as problematic was found in Ghostscript 9
A vulnerability classified as problematic was found in Ghostscript 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.
OSV
CVE-2022-1350: A vulnerability classified as problematic was found in GhostPCL 9
osv·2022-04-14·CVSS 7.8
CVE-2022-1350 [HIGH] CVE-2022-1350: A vulnerability classified as problematic was found in GhostPCL 9
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.
Red Hat
ghostscript: Improper release of objects in chunk_free_object during PCL to PDF conversion
vendor_redhat·2022-04-14·CVSS 4.3
CVE-2022-1350 [MEDIUM] CWE-787 ghostscript: Improper release of objects in chunk_free_object during PCL to PDF conversion
ghostscript: Improper release of objects in chunk_free_object during PCL to PDF conversion
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.
Statement: The `ghostscript` package as shipped with Red Hat Enterprise Linux is not affected by this flaw.
Package: ghostscript (Red Hat Enterprise Linux 6) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 7) - Not affected
Package: ghostscript (Red Hat Enterprise Linux
Debian
CVE-2022-1350: ghostscript - A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vul...
vendor_debian·2022·CVSS 4.3
CVE-2022-1350 [MEDIUM] CVE-2022-1350: ghostscript - A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vul...
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-3)
bullseye: open
forky: resolved (fixed in 10.0.0~dfsg-3)
sid: resolved (fixed in 10.0.0~dfsg-3)
trixie: resolved (fixed in 10.0.0~dfsg-3)
CISA
Microsoft Windows DNS Server Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 10.0
CVE-2020-1350 [CRITICAL] Microsoft Windows DNS Server Remote Code Execution Vulnerability
Vulnerability: Microsoft Windows DNS Server Remote Code Execution Vulnerability
Affected: Microsoft Windows
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
Required Action: Apply updates per vendor instructions.
Notes: Reference CISA's ED 20-03 (https://www.cisa.gov/news-events/directives/ed-20-03-mitigate-windows-dns-server-remote-code-execution-vulnerability-july-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-03. https://nvd.nist.gov/vuln/detail/CVE-2020-1350
Remediation Due Date: 2022-05-03
Red Hat
kernel: agp: insufficient pg_start parameter checking in AGPIOC_BIND and AGPIOC_UNBIND ioctls
vendor_redhat·2011-04-14·CVSS 6.9
CVE-2011-2022 [MEDIUM] kernel: agp: insufficient pg_start parameter checking in AGPIOC_BIND and AGPIOC_UNBIND ioctls
kernel: agp: insufficient pg_start parameter checking in AGPIOC_BIND and AGPIOC_UNBIND ioctls
The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.
Statement: This issue affects the versions of Linux kernel as shipped with Red Hat
Enterprise 4, 5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0927.html, https://rhn.redhat.com/errata/RHSA-2011-1350.html, and https://rhn.redhat.com/errata/RHSA-2011-1253
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-14
Published