CVE-2023-46751
published 2023-12-06CVE-2023-46751: An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.53%
71.9th percentile
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | <= 10.02.0 | — |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u3 | 10.0.0~dfsg-11+deb12u3 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg-1 | 10.02.1~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg-1 | 10.02.1~dfsg-1 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u3 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u3 (bookworm) |
| jenkins | assembla_auth_plugin | — | — |
| jenkins | aws_codecommit_trigger_plugin | — | — |
| jenkins | bitbucket_push_and_pull_request_plugin | — | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | disabled_permissions_can_be_granted_by_ssh2_easy_plugin | — | — |
| jenkins | disabled_permissions_granted_by_assembla_auth_plugin | — | — |
| jenkins | frugal_testing_plugin | — | — |
| jenkins | google_login_plugin | — | — |
| jenkins | ivy_plugin | — | — |
| jenkins | job_configuration_history_plugin | — | — |
| jenkins | non-constant_time_token_comparison_in_google_login_plugin | — | — |
| jenkins | pipeline_maven_integration_plugin | — | — |
| jenkins | qualys_container_scanning_connector_plugin | — | — |
| jenkins | ssh2_easy_plugin | — | — |
| jenkins | tap_plugin | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-798r-fxxx-hvxj: An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10
ghsa_unreviewed·2023-12-06
CVE-2023-46751 [HIGH] CWE-416 GHSA-798r-fxxx-hvxj: An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
OSV
CVE-2023-46751: An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10
osv·2023-12-06·CVSS 7.5
CVE-2023-46751 [HIGH] CVE-2023-46751: An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2023-12-12
CVE-2023-46751 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash if it wrote a TIFF file.
It was discovered that Ghostscript incorrectly handled writing TIFF files.
A remote attacker could possibly use this issue to cause Ghostscript to
crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: dangling pointer in gdev_prn_open_printer_seekable()
vendor_redhat·2023-12-06·CVSS 7.5
CVE-2023-46751 [HIGH] CWE-416 ghostscript: dangling pointer in gdev_prn_open_printer_seekable()
ghostscript: dangling pointer in gdev_prn_open_printer_seekable()
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
A flaw was found in Ghostscript. A remote attacker may use a specially crafted payload to trigger access to previously freed memory, which can potentially lead to remote code execution or an application crash.
Statement: The discovered vulnerability in the function gdev_prn_open_printer_seekable() within Artifex Ghostscript, poses a moderate severity threat due to its potential to cause a denial-of-service (DoS) condition. Exploiting this flaw involves manipulating a dangling pointer, which can lead to crashing the application. While the im
Debian
CVE-2023-46751: ghostscript - An issue was discovered in the function gdev_prn_open_printer_seekable() in Arti...
vendor_debian·2023·CVSS 7.5
CVE-2023-46751 [HIGH] CVE-2023-46751: ghostscript - An issue was discovered in the function gdev_prn_open_printer_seekable() in Arti...
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u3)
bullseye: resolved
forky: resolved (fixed in 10.02.1~dfsg-1)
sid: resolved (fixed in 10.02.1~dfsg-1)
trixie: resolved (fixed in 10.02.1~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.ghostscript.com/show_bug.cgi?id=707264https://ghostscript.com/https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=dcdbc595c13c9d11d235702dff46bb74c80f7698https://www.debian.org/security/2023/dsa-5578https://bugs.ghostscript.com/show_bug.cgi?id=707264https://ghostscript.com/https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=dcdbc595c13c9d11d235702dff46bb74c80f7698https://www.debian.org/security/2023/dsa-5578
2023-12-06
Published