Debian Ghostscript vulnerabilities
162 known vulnerabilities affecting debian/ghostscript.
Total CVEs
162
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL16HIGH59MEDIUM65LOW22
Vulnerabilities
Page 3 of 9
CVE-2009-0583P3CRITICALCVSS 9.3fixed in argyll 1.0.3-2 (bookworm)2009
CVE-2009-0583 [CRITICAL] CVE-2009-0583: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using
debian
CVE-2019-3839P3HIGHCVSS 7.8fixed in ghostscript 9.27~dfsg-1 (bookworm)2019
CVE-2019-3839 [HIGH] CVE-2019-3839: ghostscript - It was found that in ghostscript some privileged operators remained accessible f...
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Scope: local
bookworm: resolve
debian
CVE-2018-19134P3HIGHCVSS 7.8fixed in ghostscript 9.26~dfsg-1 (bookworm)2018
CVE-2018-19134 [HIGH] CVE-2018-19134: ghostscript - In Artifex Ghostscript through 9.25, the setpattern operator did not properly va...
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dic
debian
CVE-2019-10216P3HIGHCVSS 7.8fixed in ghostscript 9.27~dfsg-3.1 (bookworm)2019
CVE-2019-10216 [HIGH] CVE-2019-10216: ghostscript - In ghostscript before version 9.50, the .buildfont1 procedure did not properly s...
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
Scope: local
bookworm: resolved (fixed in 9.27
debian
CVE-2009-0584P3CRITICALCVSS 9.3fixed in argyll 1.0.3-2 (bookworm)2009
CVE-2009-0584 [CRITICAL] CVE-2009-0584: argyll - icc.c in the International Color Consortium (ICC) Format library (aka icclib), a...
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated
debian
CVE-2009-0792P3MEDIUMCVSS 9.3fixed in argyll 1.0.3-3 (bookworm)2009
CVE-2009-0792 [CRITICAL] CVE-2009-0792: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using
debian
CVE-2024-46956P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm)2024
CVE-2024-46956 [HIGH] CVE-2024-46956: ghostscript - An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Ou...
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u6)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u9)
forky: resolved (fixed in 10.04.0~dfsg-1)
sid: resolved (fixed in 10.04.0~dfsg-1)
trix
debian
CVE-2018-15910P3HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-15910 [HIGH] CVE-2018-15910: ghostscript - In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript ...
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-3)
bullseye: resolved (fixed in 9.22~dfsg-3)
forky: resolved (fixed in 9.22~dfsg-3)
sid: resolved (fixed in 9.22~dfsg-3)
debian
CVE-2020-16303P3HIGHCVSS 7.8fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16303 [HIGH] CVE-2020-16303: ghostscript - A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdev...
A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: res
debian
CVE-2023-46751P3HIGHCVSS 7.5fixed in ghostscript 10.0.0~dfsg-11+deb12u3 (bookworm)2023
CVE-2023-46751 [HIGH] CVE-2023-46751: ghostscript - An issue was discovered in the function gdev_prn_open_printer_seekable() in Arti...
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u3)
bullseye: resolved
forky: resolved (fixed in 10.02.1~dfsg-1)
sid: resolved (fixed in 10.02.1~dfsg-1)
trixie: reso
debian
CVE-2024-46954P3LOWCVSS 7.8fixed in ghostscript 10.04.0~dfsg-1 (forky)2024
CVE-2024-46954 [HIGH] CVE-2024-46954: ghostscript - An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript ...
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 10.04.0~dfsg-1)
sid: resolved (fixed in 10.04.0~dfsg-1)
trixie: resolved (fixed in 10.04.0~dfsg-1)
debian
CVE-2024-46953P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm)2024
CVE-2024-46953 [HIGH] CVE-2024-46953: ghostscript - An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0...
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u6)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u9)
fo
debian
CVE-2018-15909P3HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-15909 [HIGH] CVE-2018-15909: ghostscript - In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfil...
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-3)
bullseye: resolved (fixed in 9.22~dfsg-3)
forky: resolved (fixed in 9.22~dfsg-3)
sid: resolved (f
debian
CVE-2018-16802P3HIGHCVSS 7.8fixed in ghostscript 9.25~dfsg-1 (bookworm)2018
CVE-2018-16802 [HIGH] CVE-2018-16802: ghostscript - An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restorati...
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.
Scope: local
bookworm: resolved (fixed in 9.25
debian
CVE-2018-15908P3HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-15908 [HIGH] CVE-2018-15908: ghostscript - In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply mali...
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-3)
bullseye: resolved (fixed in 9.22~dfsg-3)
forky: resolved (fixed in 9.22~dfsg-3)
sid: resolved (fixed in 9.22~dfsg-3)
trixie: resolved (fixed in 9.22~dfsg-3
debian
CVE-2024-46951P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm)2024
CVE-2024-46951 [HIGH] CVE-2024-46951: ghostscript - An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. A...
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u6)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u9)
forky: resolved (fixed in 10.04.0~dfsg-1)
sid: resolved (fixed in 10
debian
CVE-2012-4405P3MEDIUMCVSS 6.8fixed in argyll 1.4.0-7 (bookworm)2012
CVE-2012-4405 [MEDIUM] CVE-2012-4405: argyll - Multiple integer underflows in the icmLut_allocate function in International Col...
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a
debian
CVE-2007-6725P3MEDIUMCVSS 7.5fixed in ghostscript 8.63.dfsg.1-1 (bookworm)2007
CVE-2007-6725 [HIGH] CVE-2007-6725: ghostscript - The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versi...
The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.
Scope: local
bookworm: resolved (fixed in 8.63.dfsg.1-1)
bullseye: resolved (fixed in 8.63.dfsg.1-
debian
CVE-2008-3522P3MEDIUMCVSS 10.0fixed in ghostscript 8.64~dfsg-2 (bookworm)2008
CVE-2008-3522 [CRITICAL] CVE-2008-3522: ghostscript - Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c...
Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.
Scope: local
bookworm: resolved (fixed in 8.64~dfsg-2)
bullseye: resolved (fixed in 8.64~dfsg-2)
forky: resolved (fixed in 8.64~
debian
CVE-2018-15911P3HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-15911 [HIGH] CVE-2018-15911: ghostscript - In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted ...
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-3)
bullseye: resolved (fixed in 9.22~dfsg-3)
forky: resolved (fixed in 9.22~dfsg-3)
sid: resolved (fixe
debian