cbcvebase.

Debian Ghostscript vulnerabilities

162 known vulnerabilities affecting debian/ghostscript.

Total CVEs
162
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL16HIGH59MEDIUM65LOW22

Vulnerabilities

Page 4 of 9
CVE-2018-16511P3HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-16511 [HIGH] CVE-2018-16511: ghostscript - An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in ... An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 9.22~dfsg-3) bullseye: resolved (fixed in 9.22~dfsg-3) forky: resolved (fixed in 9.22~dfsg-3) sid:
debian
CVE-2025-27830P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u7 (bookworm)2025
CVE-2025-27830 [HIGH] CVE-2025-27830: ghostscript - An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow... An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c. Scope: local bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u7) bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u10) forky: resolved (fixed in 10.05.0~dfsg-1) sid: resolved (fixed in 10.05.0
debian
CVE-2016-8602P3HIGHCVSS 7.8fixed in ghostscript 9.19~dfsg-3.1 (bookworm)2016
CVE-2016-8602 [HIGH] CVE-2016-8602: ghostscript - The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remot... The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Postscript document that calls .sethalftone5 with an empty operand stack. Scope: local bookworm: resolved (fixed in 9.19~dfsg-3.1) bullseye: resolved (fixed in 9.19~dfsg-3.1) f
debian
CVE-2017-9835P3HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-1 (bookworm)2017
CVE-2017-9835 [HIGH] CVE-2017-9835: ghostscript - The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allo... The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document. This is related to a lack of an integer overflow check in base/gsalloc.c. Scope: local bookworm: resolved (fi
debian
CVE-2018-17183P3HIGHCVSS 7.8fixed in ghostscript 9.25~dfsg-1 (bookworm)2018
CVE-2018-17183 [HIGH] CVE-2018-17183: ghostscript - Artifex Ghostscript before 9.25 allowed a user-writable error exception table, w... Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code. Scope: local bookworm: resolved (fixed in 9.25~dfsg-1) bullseye: resolved (fixed in 9.25~dfsg-1) forky: resolved (fixed in 9.25~dfsg-1) sid: res
debian
CVE-2018-16510P3HIGHCVSS 7.8fixed in ghostscript 9.25~dfsg-1 (bookworm)2018
CVE-2018-16510 [HIGH] CVE-2018-16510: ghostscript - An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack... An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 9.25~dfsg-1) bullseye: resolved (fixed in 9.25~dfsg-1) forky: reso
debian
CVE-2018-16585P3HIGHCVSS 7.8fixed in ghostscript 9.25~dfsg-1 (bookworm)2018
CVE-2018-16585 [HIGH] CVE-2018-16585: ghostscript - An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkey... An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other
debian
CVE-2025-27835P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u7 (bookworm)2025
CVE-2025-27835 [HIGH] CVE-2025-27835: ghostscript - An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow... An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c. Scope: local bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u7) bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u10) forky: resolved (fixed in 10.05.0~dfsg-1) sid: resolved (fixed in 10.05.0~dfsg-1) trixie: resolved (fixed
debian
CVE-2016-10317P3HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-2.1 (bookworm)2016
CVE-2016-10317 [HIGH] CVE-2016-10317: ghostscript - The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, I... The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document. Scope: local bookworm: resolved (fixed in 9.22~dfsg-2.1) bullseye: resolved (fixed
debian
CVE-2018-16540P3HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-16540 [HIGH] CVE-2018-16540: ghostscript - In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript ... In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 9.22~dfsg-3) bullseye: resolved (fixed in 9.22~dfsg-3) forky: resolved (fixed in 9.22~d
debian
CVE-2024-46952P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm)2024
CVE-2024-46952 [HIGH] CVE-2024-46952: ghostscript - An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0.... An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values). Scope: local bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u6) bullseye: resolved forky: resolved (fixed in 10.04.0~dfsg-1) sid: resolved (fixed in 10.04.0~dfsg-1) trixie: resolved (fixed
debian
CVE-2025-27834P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u7 (bookworm)2025
CVE-2025-27834 [HIGH] CVE-2025-27834: ghostscript - An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow... An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c. Scope: local bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u7) bullseye: resolved forky: resolved (fixed in 10.05.0~dfsg-1) sid: resolved (fixed in 10.05.0~dfsg-1) trixie: resolved (fixed in 10.05.0~dfsg
debian
CVE-2025-27833P3HIGHCVSS 7.8fixed in ghostscript 10.0.0~dfsg-11+deb12u7 (bookworm)2025
CVE-2025-27833 [HIGH] CVE-2025-27833: ghostscript - An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow... An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c. Scope: local bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u7) bullseye: resolved forky: resolved (fixed in 10.05.0~dfsg-1) sid: resolved (fixed in 10.05.0~dfsg-1) trixie: resolved (fixed in 10.05.0~dfsg-1)
debian
CVE-2009-3560P4LOWCVSS 5.0fixed in audacity 1.3.2-1 (bookworm)2009
CVE-2009-3560 [MEDIUM] CVE-2009-3560: audacity - The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in ... The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-20
debian
CVE-2022-1350P3LOWCVSS 4.3fixed in ghostscript 10.0.0~dfsg-3 (bookworm)2022
CVE-2022-1350 [MEDIUM] CVE-2022-1350: ghostscript - A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vul... A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It
debian
CVE-2009-3720P4LOWCVSS 5.0fixed in audacity 1.3.2-1 (bookworm)2009
CVE-2009-3720 [MEDIUM] CVE-2009-3720: audacity - The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as ... The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625. Scope: local bookwor
debian
CVE-2017-9726P4HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-1 (bookworm)2017
CVE-2017-9726 [HIGH] CVE-2017-9726: ghostscript - The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 al... The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document. Scope: local bookworm: resolved (fixed in 9.22~dfsg-1) bullseye: resolved (fixed in 9.22~dfsg-1) forky: resolved (fix
debian
CVE-2016-7977P4HIGHCVSS 5.5fixed in ghostscript 9.19~dfsg-3.1 (bookworm)2016
CVE-2016-7977 [MEDIUM] CVE-2016-7977: ghostscript - Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode pr... Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document. Scope: local bookworm: resolved (fixed in 9.19~dfsg-3.1) bullseye: resolved (fixed in 9.19~dfsg-3.1) forky: resolved (fixed in 9.19~dfsg-3.1) sid: resolved
debian
CVE-2024-33870P4MEDIUMCVSS 6.3fixed in ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm)2024
CVE-2024-33870 [MEDIUM] CVE-2024-33870: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. There is path tra... An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted. Scope: local bookworm: resolved (fixed in 10.0.0~d
debian
CVE-2017-9739P4HIGHCVSS 7.8fixed in ghostscript 9.22~dfsg-1 (bookworm)2017
CVE-2017-9739 [HIGH] CVE-2017-9739: ghostscript - The Ins_JMPR function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 al... The Ins_JMPR function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document. Scope: local bookworm: resolved (fixed in 9.22~dfsg-1) bullseye: resolved (fixed in 9.22~dfsg-1) forky: resolved (fix
debian
Debian Ghostscript vulnerabilities | cvebase