Debian Ghostscript vulnerabilities
162 known vulnerabilities affecting debian/ghostscript.
Total CVEs
162
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL16HIGH59MEDIUM65LOW22
Vulnerabilities
Page 1 of 9
CVE-2017-8291P1HIGHCVSS 7.8KEVPoCfixed in ghostscript 9.20~dfsg-3.1 (bookworm)2017
CVE-2017-8291 [HIGH] CVE-2017-8291: ghostscript - Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command ...
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.
Scope: local
bookworm: resolved (fixed in 9.20~dfsg-3.1)
bullseye: resolved (fixed in 9.20~dfsg-3.1)
for
debian
CVE-2018-16509P1HIGHCVSS 7.8ExploitedPoCfixed in ghostscript 9.25~dfsg-1 (bookworm)2018
CVE-2018-16509 [HIGH] CVE-2018-16509: ghostscript - An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restorati...
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
Scope: local
bookworm: resolved (fixed in 9.25~dfsg-1)
bullseye: resolved (fixed in 9.25~dfsg-1)
forky: re
debian
CVE-2024-29510P1MEDIUMCVSS 6.3ExploitedPoCfixed in ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm)2024
CVE-2024-29510 [MEDIUM] CVE-2024-29510: ghostscript - Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox b...
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u4)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u7)
forky: resolved (fixed in 10.03.1~dfsg~git20240518-1)
sid: resolved (fixed in 10.03.1~dfsg~git20240518-1)
debian
CVE-2021-3781P2CRITICALCVSS 9.9fixed in ghostscript 9.53.3~dfsg-8 (bookworm)2021
CVE-2021-3781 [CRITICAL] CVE-2021-3781: ghostscript - A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in t...
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integ
debian
CVE-2019-6116P2HIGHCVSS 7.8PoCfixed in ghostscript 9.26a~dfsg-1 (bookworm)2019
CVE-2019-6116 [HIGH] CVE-2019-6116: ghostscript - In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow...
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
Scope: local
bookworm: resolved (fixed in 9.26a~dfsg-1)
bullseye: resolved (fixed in 9.26a~dfsg-1)
forky: resolved (fixed in 9.26a~dfsg-1)
sid: resolved (fixed in 9.26a~dfsg-1)
trixie: resolved (fixed in 9.26a~dfsg-1)
debian
CVE-2018-17961P3HIGHCVSS 7.8PoCfixed in ghostscript 9.25~dfsg-3 (bookworm)2018
CVE-2018-17961 [HIGH] CVE-2018-17961: ghostscript - Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protec...
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
Scope: local
bookworm: resolved (fixed in 9.25~dfsg-3)
bullseye: resolved (fixed in 9.25~dfsg-3)
forky: resolved (fixed in 9.25~dfsg-3)
sid: resolved (fix
debian
CVE-2010-1869P3CRITICALCVSS 9.3PoCfixed in ghostscript 8.71~dfsg-4 (bookworm)2010
CVE-2010-1869 [CRITICAL] CVE-2010-1869: ghostscript - Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 ...
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
Scope: local
bookworm: resolved (fixed in 8.71~dfsg-4)
bullseye: resolved (fixed in 8.71~dfsg-4)
forky: resolved (fixed in 8.71~dfsg-4)
sid: resolved (fixed in 8.71~dfsg-4)
trixie: resolved
debian
CVE-2019-14813P2CRITICALCVSS 9.8fixed in ghostscript 9.28~~rc2~dfsg-1 (bookworm)2019
CVE-2019-14813 [CRITICAL] CVE-2019-14813: ghostscript - A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparam...
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Scope: local
bookwor
debian
CVE-2016-7976P2HIGHCVSS 8.8fixed in ghostscript 9.19~dfsg-3.1 (bookworm)2016
CVE-2016-7976 [HIGH] CVE-2016-7976: ghostscript - The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execu...
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
Scope: local
bookworm: resolved (fixed in 9.19~dfsg-3.1)
bullseye: resolved (fixed in 9.19~dfsg-3.1)
forky: resolved (fixed in 9.19~dfsg-3.1)
sid: resolved (fixed in 9.19~dfsg-3.1)
trixie: resolved (fixed in 9.19~dfsg-3.1)
debian
CVE-2008-0411P3MEDIUMCVSS 6.8PoCfixed in ghostscript 8.61.dfsg.1-1.1 (bookworm)2008
CVE-2008-0411 [MEDIUM] CVE-2008-0411: ghostscript - Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscrip...
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
Scope: local
bookworm: resolved (fixed in 8.61.dfsg.1-1.1)
bullseye: resolved (fixed in 8.61.dfsg.1-1.1)
forky: resolved (fixed i
debian
CVE-2023-43115P2HIGHCVSS 8.8fixed in ghostscript 10.0.0~dfsg-11+deb12u2 (bookworm)2023
CVE-2023-43115 [HIGH] CVE-2023-43115: ghostscript - In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote...
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execu
debian
CVE-2016-7979P3CRITICALCVSS 9.8fixed in ghostscript 9.19~dfsg-3.1 (bookworm)2016
CVE-2016-7979 [CRITICAL] CVE-2016-7979: ghostscript - Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode pr...
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
Scope: local
bookworm: resolved (fixed in 9.19~dfsg-3.1)
bullseye: resolved (fixed in 9.19~dfsg-3.1)
forky: resolved (fixed in 9.19~dfsg-3.1)
sid: resolved (fixed in 9
debian
CVE-2023-28879P3CRITICALCVSS 9.8fixed in ghostscript 10.0.0~dfsg-11 (bookworm)2023
CVE-2023-28879 [CRITICAL] CVE-2023-28879: ghostscript - In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to po...
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
Sco
debian
CVE-2016-7978P3CRITICALCVSS 9.8fixed in ghostscript 9.19~dfsg-3.1 (bookworm)2016
CVE-2016-7978 [CRITICAL] CVE-2016-7978: ghostscript - Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to...
Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.
Scope: local
bookworm: resolved (fixed in 9.19~dfsg-3.1)
bullseye: resolved (fixed in 9.19~dfsg-3.1)
forky: resolved (fixed in 9.19~dfsg-3.1)
sid: resolved (fixed in 9.19~dfsg-3.1)
trixie: resolved (fixe
debian
CVE-2019-14869P3HIGHCVSS 8.8fixed in ghostscript 9.50~dfsg-3 (bookworm)2019
CVE-2019-14869 [HIGH] CVE-2019-14869: ghostscript - A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.cha...
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside
debian
CVE-2025-27831P3CRITICALCVSS 9.8fixed in ghostscript 10.0.0~dfsg-11+deb12u7 (bookworm)2025
CVE-2025-27831 [CRITICAL] CVE-2025-27831: ghostscript - An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXT...
An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u7)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u10)
forky: resolved (fixed in 10.05.0~dfsg-1)
sid: resolved (fixed in 10.
debian
CVE-2018-18284P3HIGHCVSS 8.6fixed in ghostscript 9.25~dfsg-3 (bookworm)2018
CVE-2018-18284 [HIGH] CVE-2018-18284: ghostscript - Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protec...
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
Scope: local
bookworm: resolved (fixed in 9.25~dfsg-3)
bullseye: resolved (fixed in 9.25~dfsg-3)
forky: resolved (fixed in 9.25~dfsg-3)
sid: resolved (fixed in 9.25~dfsg-3)
trixie: resolved (fixed in 9.25~dfsg-3)
debian
CVE-2025-27832P3CRITICALCVSS 9.8fixed in ghostscript 10.0.0~dfsg-11+deb12u7 (bookworm)2025
CVE-2025-27832 [CRITICAL] CVE-2025-27832: ghostscript - An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device h...
An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u7)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u10)
forky: resolved (fixed in 10.05.0~dfsg-1)
sid: resolved (fixed in 10.05.0~dfsg-1)
trixie: resol
debian
CVE-2025-27836P3CRITICALCVSS 9.8fixed in ghostscript 10.0.0~dfsg-11+deb12u7 (bookworm)2025
CVE-2025-27836 [CRITICAL] CVE-2025-27836: ghostscript - An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device ...
An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u7)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u10)
forky: resolved (fixed in 10.05.0~dfsg-1)
sid: resolved (fixed in 10.05.0~dfsg-1)
trixie: resolved (fi
debian
CVE-2024-33871P3HIGHCVSS 8.8fixed in ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm)2024
CVE-2024-33871 [HIGH] CVE-2024-33871: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdev...
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.
Scope: local
bookworm
debian
1 / 9Next →