CVE-2023-28879
published 2023-03-31CVE-2023-28879: In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.34%
92.9th percentile
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.01.0 | 10.01.0 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u4 | 9.53.3~dfsg-7+deb11u4 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11 | 10.0.0~dfsg-11 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11 | 10.0.0~dfsg-11 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11 | 10.0.0~dfsg-11 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11 (bookworm) | ghostscript 10.0.0~dfsg-11 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is in base/sbcp.c within Ghostscript; monitor for exploitation attempts targeting BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode functions ↗
- →Trigger condition is a write buffer filled to one byte less than full followed by an escaped character write — look for crafted PostScript inputs that produce two-byte writes in BCP encode/decode paths ↗
- →Affected versions are Ghostscript through 10.01.0; flag any process invocations of ghostscript/gs binaries at or below this version processing untrusted PostScript input ↗
- →Successful exploitation may lead to arbitrary code execution running as the login user — alert on unexpected child processes spawned from gs/ghostscript ↗
- ·Scope is listed as local by Debian security tracker, meaning exploitation typically requires local or authenticated access to supply crafted input to Ghostscript ↗
- ·Red Hat Enterprise Linux 8 (gimp:flatpak/ghostscript) is marked 'Will not fix', so patching cannot be relied upon as a control on that platform ↗
- ·RHEL 6 and RHEL 7 packages are out of support scope — no vendor patch will be provided for those versions ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2023-04-26
CVE-2023-28879 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash or run programs as your login if it
received a specially crafted input.
USN-6017-1 fixed vulnerabilities in Ghostscript. This update provides the
corresponding updates for Ubuntu 23.04.
Original advisory details:
Hadrien Perrineau discovered that Ghostscript incorrectly handled certain
inputs. An attacker could possibly use this issue to cause a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2023-04-13
CVE-2023-28879 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash or run programs as your login if it
received a specially crafted input.
Hadrien Perrineau discovered that Ghostscript incorrectly handled certain
inputs. An attacker could possibly use this issue to cause a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: buffer overflow in base/sbcp.c leading to data corruption
vendor_redhat·2023-03-31·CVSS 9.8
CVE-2023-28879 [CRITICAL] CWE-787 ghostscript: buffer overflow in base/sbcp.c leading to data corruption
ghostscript: buffer overflow in base/sbcp.c leading to data corruption
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
Package: ghostscript (Red Hat Enterprise Linux 6) - Out of support scope
Package: ghostscript (Red Hat Enterprise Linux 7) - Out of support scope
Package: gimp:flatpak/ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2023-28879: ghostscript - In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to po...
vendor_debian·2023·CVSS 9.8
CVE-2023-28879 [CRITICAL] CVE-2023-28879: ghostscript - In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to po...
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u4)
forky: resolved (fixed in 10.0.0~dfsg-11)
sid: resolved (fixed in 10.0.0~dfsg-11)
trixie: resolved (fixed in 10.0.0~dfsg-11)
GHSA
GHSA-6mcj-frmm-wmr5: In Artifex Ghostscript through 10
ghsa_unreviewed·2023-03-31
CVE-2023-28879 [CRITICAL] CWE-787 GHSA-6mcj-frmm-wmr5: In Artifex Ghostscript through 10
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
OSV
CVE-2023-28879: In Artifex Ghostscript through 10
osv·2023-03-31·CVSS 9.8
CVE-2023-28879 [CRITICAL] CVE-2023-28879: In Artifex Ghostscript through 10
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/04/12/4https://bugs.ghostscript.com/show_bug.cgi?id=706494https://ghostscript.readthedocs.io/en/latest/News.htmlhttps://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=37ed5022cecd584de868933b5b60da2e995b3179https://lists.debian.org/debian-lts-announce/2023/04/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHJX62KSRIOBZA6FKONMJP7MEFY7LTH2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MADLP3GWJFLLFVNZGEDNPMDQR6CCXAHN/https://security.gentoo.org/glsa/202309-03https://www.debian.org/security/2023/dsa-5383http://www.openwall.com/lists/oss-security/2023/04/12/4https://bugs.ghostscript.com/show_bug.cgi?id=706494https://ghostscript.readthedocs.io/en/latest/News.htmlhttps://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=37ed5022cecd584de868933b5b60da2e995b3179https://lists.debian.org/debian-lts-announce/2023/04/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHJX62KSRIOBZA6FKONMJP7MEFY7LTH2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MADLP3GWJFLLFVNZGEDNPMDQR6CCXAHN/https://security.gentoo.org/glsa/202309-03https://www.debian.org/security/2023/dsa-5383
2023-03-31
Published