cbcvebase.
CVE-2023-28879
published 2023-03-31

CVE-2023-28879: In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in…

PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.34%
92.9th percentile
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

Affected

8 ranges
VendorProductVersion rangeFixed in
artifexghostscript< 10.01.010.01.0
artifexghostscript>= 0 < 9.53.3~dfsg-7+deb11u49.53.3~dfsg-7+deb11u4
artifexghostscript>= 0 < 10.0.0~dfsg-1110.0.0~dfsg-11
artifexghostscript>= 0 < 10.0.0~dfsg-1110.0.0~dfsg-11
artifexghostscript>= 0 < 10.0.0~dfsg-1110.0.0~dfsg-11
debiandebian_linux
debiandebian_linux
debianghostscript< ghostscript 10.0.0~dfsg-11 (bookworm)ghostscript 10.0.0~dfsg-11 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in base/sbcp.c within Ghostscript; monitor for exploitation attempts targeting BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode functions
  • Trigger condition is a write buffer filled to one byte less than full followed by an escaped character write — look for crafted PostScript inputs that produce two-byte writes in BCP encode/decode paths
  • Affected versions are Ghostscript through 10.01.0; flag any process invocations of ghostscript/gs binaries at or below this version processing untrusted PostScript input
  • Successful exploitation may lead to arbitrary code execution running as the login user — alert on unexpected child processes spawned from gs/ghostscript
  • ·Scope is listed as local by Debian security tracker, meaning exploitation typically requires local or authenticated access to supply crafted input to Ghostscript
  • ·Red Hat Enterprise Linux 8 (gimp:flatpak/ghostscript) is marked 'Will not fix', so patching cannot be relied upon as a control on that platform
  • ·RHEL 6 and RHEL 7 packages are out of support scope — no vendor patch will be provided for those versions

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.