CVE-2023-52722
published 2024-04-28CVE-2023-52722: An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.33%
25.5th percentile
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.03.1 | 10.03.1 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u7 | 9.53.3~dfsg-7+deb11u7 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u4 | 10.0.0~dfsg-11+deb12u4 |
| artifex | ghostscript | >= 0 < 10.02.0~dfsg-1 | 10.02.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.02.0~dfsg-1 | 10.02.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.12 | 9.50~dfsg-5ubuntu4.12 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.7 | 9.55.0~dfsg1-0ubuntu5.7 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.1 | 10.02.1~dfsg1-0ubuntu7.1 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ghostscript vulnerabilities
osv·2024-06-17·CVSS 5.5
CVE-2023-52722 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript did not properly restrict eexec
seeds to those specified by the Type 1 Font Format standard when
SAFER mode is used. An attacker could use this issue to bypass SAFER
restrictions and cause unspecified impact. (CVE-2023-52722)
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.10.
Thomas Rinsma discovered that Ghostscript did not prevent changes to
uniprint device argument strings after SAFER is activated, resulting
in a format-string vulnerability. An attacker could possibly use this
to execute arbitrary code. (CVE-2024-29510)
Zdenek Hutyra discovered that Ghostscript did not properly perform
path reduction when validating paths. An attacker could use this to
access file locations outside of those all
OSV
CVE-2023-52722: An issue was discovered in Artifex Ghostscript before 10
osv·2024-04-28·CVSS 5.5
CVE-2023-52722 [MEDIUM] CVE-2023-52722: An issue was discovered in Artifex Ghostscript before 10
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
GHSA
GHSA-5473-w6gq-5r5g: An issue was discovered in Artifex Ghostscript through 10
ghsa_unreviewed·2024-04-28
CVE-2023-52722 [MEDIUM] GHSA-5473-w6gq-5r5g: An issue was discovered in Artifex Ghostscript through 10
An issue was discovered in Artifex Ghostscript through 10.01.0. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-06-17·CVSS 5.5
CVE-2024-33871 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript did not properly restrict eexec
seeds to those specified by the Type 1 Font Format standard when
SAFER mode is used. An attacker could use this issue to bypass SAFER
restrictions and cause unspecified impact. (CVE-2023-52722)
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.10.
Thomas Rinsma discovered that Ghostscript did not prevent changes to
uniprint device argument strings after SAFER is activated, resulting
in a format-string vulnerability. An attacker could possibly use this
to execute arbitrary code. (CVE-2024-29510)
Zdenek Hutyra discovered that Ghostscript did not properly perform
path reduction when validating paths. An a
Red Hat
ghostscript: eexec seeds other than the Type 1 standard are allowed while using SAFER mode
vendor_redhat·2024-04-28·CVSS 5.5
CVE-2023-52722 [MEDIUM] CWE-754 ghostscript: eexec seeds other than the Type 1 standard are allowed while using SAFER mode
ghostscript: eexec seeds other than the Type 1 standard are allowed while using SAFER mode
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
A vulnerability was found in Ghostscript. When the SAFER mode is used, eexec seeds other than the Type 1 standard are allowed.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: ghostscript (Red Hat Enterprise Linux 10) - Not affected
Package: ghostscript (Red Hat Enterprise Linux 6) - Out of support scope
Package: ghostscript (Red Hat Enterpri
Debian
CVE-2023-52722: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, whe...
vendor_debian·2023·CVSS 5.5
CVE-2023-52722 [MEDIUM] CVE-2023-52722: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, whe...
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u4)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u7)
forky: resolved (fixed in 10.02.0~dfsg-1)
sid: resolved (fixed in 10.02.0~dfsg-1)
trixie: resolved (fixed in 10.02.0~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/06/28/2https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=afd7188f74918cb51b5fb89f52b54eb16e8acfd1http://www.openwall.com/lists/oss-security/2024/06/28/2https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=afd7188f74918cb51b5fb89f52b54eb16e8acfd1
2024-04-28
Published