CVE-2023-43115
published 2023-09-18CVE-2023-43115: In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the…
PriorityP259high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.68%
90.8th percentile
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | <= 10.01.2 | — |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u6 | 9.53.3~dfsg-7+deb11u6 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u2 | 10.0.0~dfsg-11+deb12u2 |
| artifex | ghostscript | >= 0 < 10.02.0~dfsg-1 | 10.02.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.02.0~dfsg-1 | 10.02.0~dfsg-1 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u2 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted PostScript documents that attempt to switch to the IJS device after SAFER mode has been activated ↗
- →Monitor for changes to the IjsServer parameter in PostScript/PDF processing pipelines, especially after SAFER activation, as this can be used to execute arbitrary commands via the IJS server ↗
- →Flag Ghostscript (gs) process invocations that spawn unexpected child processes, as exploitation of the IJS device causes Ghostscript to execute an external IJS server command ↗
- →Alert on automated or user-driven opening of PDF/PostScript files with Ghostscript versions through 10.01.2, particularly in unattended processing pipelines ↗
- ·The IJS device and IjsServer parameter are legitimate Ghostscript features; the vulnerability arises specifically from their use AFTER SAFER mode is activated. Detection logic must account for the SAFER bypass context to avoid false positives on normal IJS usage. ↗
- ·Red Hat Enterprise Linux 7 and 8 are listed as Not Affected; scope detections to vulnerable platforms (RHEL 6 out of support, Debian bookworm/bullseye unpatched, Ghostscript ≤ 10.01.2). ↗
- ·The vulnerable source file is gdevijs.c within GhostPDL; patch verification should confirm this file is updated to a fixed version (Debian: 10.0.0~dfsg-11+deb12u2 for bookworm, 9.53.3~dfsg-7+deb11u6 for bullseye, 10.02.0~dfsg-1 for sid/trixie/forky). ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2023-10-17
CVE-2023-43115 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to run programs if it opened a specially crafted
file.
It was discovered that Ghostscript incorrectly handled certain PDF
documents. If a user or automated system were tricked into opening a
specially crafted PDF file, a remote attacker could use this issue to
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Ghostscript: GhostPDL can lead to remote code execution via crafted PostScript documents
vendor_redhat·2023-09-18·CVSS 8.8
CVE-2023-43115 [HIGH] CWE-94 Ghostscript: GhostPDL can lead to remote code execution via crafted PostScript documents
Ghostscript: GhostPDL can lead to remote code execution via crafted PostScript documents
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).
A vulnerability was found in Artifex Ghostscript in gdevijs.c, allows a malicious remote attacker to perform remote code execution via crafted PostScript documents.
Package: ghostscript (Red Hat Enterprise Linux 6) - Out of support scope
Package: ghostscript (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2023-43115: ghostscript - In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote...
vendor_debian·2023·CVSS 8.8
CVE-2023-43115 [HIGH] CVE-2023-43115: ghostscript - In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote...
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u2)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u6)
forky: resolved (fixed in 10.02.0~dfsg-1)
sid: resolved (fixed in 10.02.0~dfsg-1)
trixie: resolved (fixed in 10.02.0~dfsg-1)
GHSA
GHSA-9p55-888j-qxrh: In Artifex Ghostscript through 10
ghsa_unreviewed·2023-09-18
CVE-2023-43115 [HIGH] GHSA-9p55-888j-qxrh: In Artifex Ghostscript through 10
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).
OSV
CVE-2023-43115: In Artifex Ghostscript through 10
osv·2023-09-18·CVSS 8.8
CVE-2023-43115 [HIGH] CVE-2023-43115: In Artifex Ghostscript through 10
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.ghostscript.com/show_bug.cgi?id=707051https://ghostscript.com/https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=e59216049cac290fb437a04c4f41ea46826cfba5https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IK3UXJ5HKMPAL5EQELJAWSRPA2AUOJJO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PG5AQV7JOL5TAU76FWPJCMSKO5DREKV5/https://bugs.ghostscript.com/show_bug.cgi?id=707051https://ghostscript.com/https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=e59216049cac290fb437a04c4f41ea46826cfba5https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IK3UXJ5HKMPAL5EQELJAWSRPA2AUOJJO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PG5AQV7JOL5TAU76FWPJCMSKO5DREKV5/
2023-09-18
Published