Debian Ghostscript vulnerabilities
162 known vulnerabilities affecting debian/ghostscript.
Total CVEs
162
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL16HIGH59MEDIUM65LOW22
Vulnerabilities
Page 2 of 9
CVE-2018-19475P3HIGHCVSS 7.8fixed in ghostscript 9.26~dfsg-1 (bookworm)2018
CVE-2018-19475 [HIGH] CVE-2018-19475: ghostscript - psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to byp...
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
Scope: local
bookworm: resolved (fixed in 9.26~dfsg-1)
bullseye: resolved (fixed in 9.26~dfsg-1)
forky: resolved (fixed in 9.26~dfsg-1)
sid: resolved (fixed in 9.26~dfsg-1)
debian
CVE-2018-19409P3CRITICALCVSS 9.8fixed in ghostscript 9.26~dfsg-1 (bookworm)2018
CVE-2018-19409 [CRITICAL] CVE-2018-19409: ghostscript - An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is ...
An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.
Scope: local
bookworm: resolved (fixed in 9.26~dfsg-1)
bullseye: resolved (fixed in 9.26~dfsg-1)
forky: resolved (fixed in 9.26~dfsg-1)
sid: resolved (fixed in 9.26~dfsg-1)
trixie: resolved (fixed in 9.26~dfsg-1)
debian
CVE-2009-0196P3MEDIUMCVSS 9.3fixed in ghostscript 8.64~dfsg-1.1 (bookworm)2009
CVE-2009-0196 [CRITICAL] CVE-2009-0196: ghostscript - Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol...
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
Scope: local
bookworm: resolved (fixed in 8.6
debian
CVE-2020-15900P3CRITICALCVSS 9.8fixed in ghostscript 9.52.1~dfsg-1 (bookworm)2020
CVE-2020-15900 [CRITICAL] CVE-2020-15900: ghostscript - A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of...
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
Scope: lo
debian
CVE-2009-3743P3CRITICALCVSS 9.3fixed in ghostscript 8.71~dfsg-1 (bookworm)2009
CVE-2009-3743 [CRITICAL] CVE-2009-3743: ghostscript - Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter...
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed
debian
CVE-2024-29506P3HIGHCVSS 8.8fixed in ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm)2024
CVE-2024-29506 [HIGH] CVE-2024-29506: ghostscript - Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi...
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u5)
bullseye: resolved
forky: resolved (fixed in 10.03.0~dfsg-1)
sid: resolved (fixed in 10.03.0~dfsg-1)
trixie: resolved (fixed in 10.03.0~dfsg-1)
debian
CVE-2020-36773P3CRITICALCVSS 9.8fixed in ghostscript 9.53.0~dfsg-1 (bookworm)2020
CVE-2020-36773 [CRITICAL] CVE-2020-36773: ghostscript - Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free ...
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
Scope: local
bookworm: resolved (fixed in 9.53.0~dfsg-1)
bullseye: resolved (fixed in 9.53.0~dfsg-1)
forky: resolved (
debian
CVE-2009-4270P3MEDIUMCVSS 9.3fixed in ghostscript 8.70~dfsg-2.1 (bookworm)2009
CVE-2009-4270 [CRITICAL] CVE-2009-4270: ghostscript - Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghosts...
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
Scope: local
bookworm: resolved (fixed in 8.70~dfs
debian
CVE-2009-4897P3CRITICALCVSS 9.3fixed in ghostscript 8.70~dfsg-1 (bookworm)2009
CVE-2009-4897 [CRITICAL] CVE-2009-4897: ghostscript - Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote ...
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
Scope: local
bookworm: resolved (fixed in 8.70~dfsg-1)
bullseye: resolved (fixed in 8.70~dfsg-1)
forky: resolved (fixed in 8.70~dfsg-1)
sid: resol
debian
CVE-2019-14811P3HIGHCVSS 7.8fixed in ghostscript 9.28~~rc2~dfsg-1 (bookworm)2019
CVE-2019-14811 [HIGH] CVE-2019-14811: ghostscript - A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Cr...
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Scope: local
bookwor
debian
CVE-2011-4517P3MEDIUMCVSS 6.8fixed in ghostscript 8.64~dfsg-2 (bookworm)2011
CVE-2011-4517 [MEDIUM] CVE-2011-4517: ghostscript - The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses a...
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 fi
debian
CVE-2011-4516P3MEDIUMCVSS 6.8fixed in ghostscript 8.64~dfsg-2 (bookworm)2011
CVE-2011-4516 [MEDIUM] CVE-2011-4516: ghostscript - Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc...
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
Scope: local
bookworm: resolved (fixed in 8.64~dfsg-2)
bullse
debian
CVE-2010-1628P3MEDIUMCVSS 9.3fixed in ghostscript 8.71~dfsg2-4 (bookworm)2010
CVE-2010-1628 [CRITICAL] CVE-2010-1628: ghostscript - Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent att...
Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
Scope: local
bookworm: resolved (fixed in 8.71~dfsg2-4)
bullseye: resolved (fixed in 8.71~dfsg2-4)
forky: re
debian
CVE-2024-29511P3LOWCVSS 7.5fixed in ghostscript 10.03.0~dfsg-1 (forky)2024
CVE-2024-29511 [HIGH] CVE-2024-29511: ghostscript - Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a direct...
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10
debian
CVE-2024-29509P3HIGHCVSS 8.8fixed in ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm)2024
CVE-2024-29509 [HIGH] CVE-2024-29509: ghostscript - Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e...
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u5)
bullseye: resolved
forky: resolved (fixed in 10.03.0~dfsg-1)
sid: resolved (fixed in 10.03.0~dfsg-1)
trixie: resolved (fixed in 10.03.0~dfsg-1)
debian
CVE-2018-19477P3HIGHCVSS 7.8fixed in ghostscript 9.26~dfsg-1 (bookworm)2018
CVE-2018-19477 [HIGH] CVE-2018-19477: ghostscript - psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypa...
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
Scope: local
bookworm: resolved (fixed in 9.26~dfsg-1)
bullseye: resolved (fixed in 9.26~dfsg-1)
forky: resolved (fixed in 9.26~dfsg-1)
sid: resolved (fixed in 9.26~dfsg-1)
trixie: resolved (fixed in 9.26~dfsg-1
debian
CVE-2018-19476P3HIGHCVSS 7.8fixed in ghostscript 9.26~dfsg-1 (bookworm)2018
CVE-2018-19476 [HIGH] CVE-2018-19476: ghostscript - psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass ...
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
Scope: local
bookworm: resolved (fixed in 9.26~dfsg-1)
bullseye: resolved (fixed in 9.26~dfsg-1)
forky: resolved (fixed in 9.26~dfsg-1)
sid: resolved (fixed in 9.26~dfsg-1)
trixie: resolved (fixed in 9.26~dfsg-1)
debian
CVE-2019-14812P3HIGHCVSS 7.8fixed in ghostscript 9.28~~rc2~dfsg-1 (bookworm)2019
CVE-2019-14812 [HIGH] CVE-2019-14812: ghostscript - A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserpar...
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Scope: local
bookworm
debian
CVE-2019-14817P3HIGHCVSS 7.8fixed in ghostscript 9.28~~rc2~dfsg-1 (bookworm)2019
CVE-2019-14817 [HIGH] CVE-2019-14817: ghostscript - A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken an...
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Scope: local
book
debian
CVE-2023-36664P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u1 (bookworm)2023
CVE-2023-36664 [HIGH] CVE-2023-36664: ghostscript - Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe de...
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u1)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u5)
forky: resolved (fixed in 10.01.2~dfsg-1)
sid: resolved (fixed in 10.01.2~dfsg-1)
trixie: resolved (fix
debian