CVE-2023-38559
published 2023-08-01CVE-2023-38559: A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of…
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.45%
36.2th percentile
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.02.0 | 10.02.0 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u6 | 9.53.3~dfsg-7+deb11u6 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u2 | 10.0.0~dfsg-11+deb12u2 |
| artifex | ghostscript | >= 0 < 10.02.0~dfsg-1 | 10.02.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.02.0~dfsg-1 | 10.02.0~dfsg-1 |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u2 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2023-08-17
CVE-2023-38559 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash if it received specially crafted input.
It was discovered that Ghostscript incorrectly handled outputting certain
PDF files. A local attacker could potentially use this issue to cause
a crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: Out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in DoS
vendor_redhat·2023-07-17·CVSS 5.5
CVE-2023-38559 [MEDIUM] CWE-125 ghostscript: Out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in DoS
ghostscript: Out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in DoS
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
Package: ghostscript (Red Hat Enterprise Linux 6) - Out of support scope
Package: ghostscript (Red Hat Enterprise Linux 7) - Out of support scope
Package: gimp:flatpak/ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2023-38559: ghostscript - A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle()...
vendor_debian·2023·CVSS 5.5
CVE-2023-38559 [MEDIUM] CVE-2023-38559: ghostscript - A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle()...
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u2)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u6)
forky: resolved (fixed in 10.02.0~dfsg-1)
sid: resolved (fixed in 10.02.0~dfsg-1)
trixie: resolved (fixed in 10.02.0~dfsg-1)
GHSA
GHSA-v34c-9rwg-qpf6: A buffer overflow flaw was found in base/gdevdevn
ghsa_unreviewed·2023-08-01
CVE-2023-38559 [MEDIUM] CWE-120 GHSA-v34c-9rwg-qpf6: A buffer overflow flaw was found in base/gdevdevn
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
OSV
CVE-2023-38559: A buffer overflow flaw was found in base/gdevdevn
osv·2023-08-01·CVSS 5.5
CVE-2023-38559 [MEDIUM] CVE-2023-38559: A buffer overflow flaw was found in base/gdevdevn
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:6544https://access.redhat.com/errata/RHSA-2023:7053https://access.redhat.com/security/cve/CVE-2023-38559https://bugs.ghostscript.com/show_bug.cgi?id=706897https://bugzilla.redhat.com/show_bug.cgi?id=2224367https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=d81b82c70bc1https://access.redhat.com/errata/RHSA-2023:6544https://access.redhat.com/errata/RHSA-2023:7053https://access.redhat.com/security/cve/CVE-2023-38559https://bugs.ghostscript.com/show_bug.cgi?id=706897https://bugzilla.redhat.com/show_bug.cgi?id=2224367https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=d81b82c70bc1https://lists.debian.org/debian-lts-announce/2023/08/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/GBV6BTUREXM6DB3OGHGLMWGAZ3I45TXE/https://lists.fedoraproject.org/archives/list/[email protected]/message/QH7ERAYSSXEYDWWY7LOV7CA5MIDZN3Z6/
2023-08-01
Published