CVE-2023-4042
published 2023-08-23CVE-2023-4042: A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.33%
25.1th percentile
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 9.51 | 9.51 |
| debian | ghostscript | — | — |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ghostscript: Incomplete fix for CVE-2020-16305
vendor_redhat·2023-08-23·CVSS 5.5
CVE-2023-4042 [MEDIUM] CWE-125 ghostscript: Incomplete fix for CVE-2020-16305
ghostscript: Incomplete fix for CVE-2020-16305
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
Statement: CVE-2020-16305 affected Red Hat Enterprise Linux 6, 7, and 8, but was only intended to be fixed in Red Hat Enterprise Linux 8. (https://access.redhat.com/errata/RHSA-2021:1852 (Red Hat Enterprise Linux 8.4)
That errata provided updates for ghostscript packages,
Debian
CVE-2023-4042: ghostscript - A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was n...
vendor_debian·2023·CVSS 5.5
CVE-2023-4042 [MEDIUM] CVE-2023-4042: ghostscript - A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was n...
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-jgj3-64jr-4g3x: A flaw was found in ghostscript
ghsa_unreviewed·2023-08-23·CVSS 5.5
CVE-2023-4042 [MEDIUM] CWE-125 GHSA-jgj3-64jr-4g3x: A flaw was found in ghostscript
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:7053https://access.redhat.com/security/cve/CVE-2023-4042https://bugzilla.redhat.com/show_bug.cgi?id=1870257https://bugzilla.redhat.com/show_bug.cgi?id=2228151https://access.redhat.com/errata/RHSA-2023:7053https://access.redhat.com/security/cve/CVE-2023-4042https://bugzilla.redhat.com/show_bug.cgi?id=1870257https://bugzilla.redhat.com/show_bug.cgi?id=2228151
2023-08-23
Published