cbcvebase.
CVE-2023-43115
published 2023-09-18

CVE-2023-43115: In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the…

PriorityP259high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.68%
90.8th percentile
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).

Affected

8 ranges
VendorProductVersion rangeFixed in
artifexghostscript<= 10.01.2
artifexghostscript>= 0 < 9.53.3~dfsg-7+deb11u69.53.3~dfsg-7+deb11u6
artifexghostscript>= 0 < 10.0.0~dfsg-11+deb12u210.0.0~dfsg-11+deb12u2
artifexghostscript>= 0 < 10.02.0~dfsg-110.02.0~dfsg-1
artifexghostscript>= 0 < 10.02.0~dfsg-110.02.0~dfsg-1
debianghostscript< ghostscript 10.0.0~dfsg-11+deb12u2 (bookworm)ghostscript 10.0.0~dfsg-11+deb12u2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted PostScript documents that attempt to switch to the IJS device after SAFER mode has been activated
  • Monitor for changes to the IjsServer parameter in PostScript/PDF processing pipelines, especially after SAFER activation, as this can be used to execute arbitrary commands via the IJS server
  • Flag Ghostscript (gs) process invocations that spawn unexpected child processes, as exploitation of the IJS device causes Ghostscript to execute an external IJS server command
  • Alert on automated or user-driven opening of PDF/PostScript files with Ghostscript versions through 10.01.2, particularly in unattended processing pipelines
  • ·The IJS device and IjsServer parameter are legitimate Ghostscript features; the vulnerability arises specifically from their use AFTER SAFER mode is activated. Detection logic must account for the SAFER bypass context to avoid false positives on normal IJS usage.
  • ·Red Hat Enterprise Linux 7 and 8 are listed as Not Affected; scope detections to vulnerable platforms (RHEL 6 out of support, Debian bookworm/bullseye unpatched, Ghostscript ≤ 10.01.2).
  • ·The vulnerable source file is gdevijs.c within GhostPDL; patch verification should confirm this file is updated to a fixed version (Debian: 10.0.0~dfsg-11+deb12u2 for bookworm, 9.53.3~dfsg-7+deb11u6 for bullseye, 10.02.0~dfsg-1 for sid/trixie/forky).

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.