Debian Ghostscript vulnerabilities
162 known vulnerabilities affecting debian/ghostscript.
Total CVEs
162
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL16HIGH59MEDIUM65LOW22
Vulnerabilities
Page 6 of 9
CVE-2013-5653P4LOWCVSS 5.5fixed in ghostscript 9.19~dfsg-3.1 (bookworm)2013
CVE-2013-5653 [MEDIUM] CVE-2013-5653: ghostscript - The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER"...
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.
Scope: local
bookworm: resolved (fixed in 9.19~dfsg-3.1)
bullseye: resolved (fixed in 9.19~dfsg-3.1)
forky: resolved (fixed in 9.19~dfsg-3.1)
sid: resolved (fixed in 9.19~dfsg-3.1)
trixie: resolved (
debian
CVE-2017-9619P4LOWCVSS 7.8fixed in ghostscript 9.22~dfsg-1 (bookworm)2017
CVE-2017-9619 [HIGH] CVE-2017-9619: ghostscript - The xps_true_callback_glyph_name function in xps/xpsttf.c in Artifex Ghostscript...
The xps_true_callback_glyph_name function in xps/xpsttf.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (Segmentation Violation and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-1)
bullseye: resolved (fixed in 9.22~dfsg-1)
forky: resolved (fixed in 9.22~dfsg-1)
sid: resolved (
debian
CVE-2010-2055P4HIGHCVSS 7.2fixed in ghostscript 8.71~dfsg2-6.1 (bookworm)2010
CVE-2010-2055 [HIGH] CVE-2010-2055: ghostscript - Ghostscript 8.71 and earlier reads initialization files from the current working...
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
Scope: local
bookworm: resolved (fixe
debian
CVE-2024-29507P4MEDIUMCVSS 5.4fixed in ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm)2024
CVE-2024-29507 [MEDIUM] CVE-2024-29507: ghostscript - Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow v...
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u5)
bullseye: resolved
forky: resolved (fixed in 10.03.0~dfsg-1)
sid: resolved (fixed in 10.03.0~dfsg-1)
trixie: resolved (fixed in 10.03.0~dfsg-1)
debian
CVE-2018-18073P4MEDIUMCVSS 6.3fixed in ghostscript 9.25~dfsg-3 (bookworm)2018
CVE-2018-18073 [MEDIUM] CVE-2018-18073: ghostscript - Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by...
Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.
Scope: local
bookworm: resolved (fixed in 9.25~dfsg-3)
bullseye: resolved (fixed in 9.25~dfsg-3)
forky: resolved (fixed in 9.25~dfsg-3)
sid: resolved (fixed in 9.25~dfsg-3)
trixie: resolved (f
debian
CVE-2020-27792P4HIGHCVSS 7.1fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-27792 [HIGH] CVE-2020-27792: ghostscript - A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_pr...
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye:
debian
CVE-2025-59798P4MEDIUMCVSS 4.3fixed in ghostscript 10.0.0~dfsg-11+deb12u8 (bookworm)2025
CVE-2025-59798 [MEDIUM] CVE-2025-59798: ghostscript - Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_wri...
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u8)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u11)
forky: resolved (fixed in 10.06.0~dfsg-1)
sid: resolved (fixed in 10.06.0~dfsg-1)
trixie: resolved (fixed in 10.05.1~dfsg-1+d
debian
CVE-2025-59799P4MEDIUMCVSS 4.3fixed in ghostscript 10.0.0~dfsg-11+deb12u8 (bookworm)2025
CVE-2025-59799 [MEDIUM] CVE-2025-59799: ghostscript - Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark...
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u8)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u11)
forky: resolved (fixed in 10.06.0~dfsg-1)
sid: resolved (fixed in 10.06.0~dfsg-1)
trixie: resolve
debian
CVE-2020-16304P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16304 [MEDIUM] CVE-2020-16304: ghostscript - A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor....
A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
s
debian
CVE-2020-16302P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16302 [MEDIUM] CVE-2020-16302: ghostscript - A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c o...
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: resolved
debian
CVE-2018-16539P4MEDIUMCVSS 5.5fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-16539 [MEDIUM] CVE-2018-16539: ghostscript - In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript ...
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-3)
bullseye: resolved (fixed in 9.22~dfsg-3)
forky: resolved (fixed in 9.22~dfsg-3)
sid: resolved
debian
CVE-2024-33869P4MEDIUMCVSS 5.3fixed in ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm)2024
CVE-2024-33869 [MEDIUM] CVE-2024-33869: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal an...
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u4)
b
debian
CVE-2017-15652P4MEDIUMCVSS 5.5fixed in ghostscript 9.25~dfsg-1 (bookworm)2017
CVE-2017-15652 [MEDIUM] CVE-2017-15652: ghostscript - Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obta...
Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of imagemagick also use libga, so it was affe
debian
CVE-2025-59800P4LOWCVSS 4.3fixed in ghostscript 10.06.0~dfsg-1 (forky)2025
CVE-2025-59800 [MEDIUM] CVE-2025-59800: ghostscript - In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c h...
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.06.0~dfsg-1)
sid: resolved (fixed in 10.06.0~dfsg-1)
trixie: open
debian
CVE-2020-16297P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16297 [MEDIUM] CVE-2020-16297: ghostscript - A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjc...
A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~d
debian
CVE-2020-16296P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16296 [MEDIUM] CVE-2020-16296: ghostscript - A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c...
A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51
debian
CVE-2020-17538P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-17538 [MEDIUM] CVE-2020-17538: ghostscript - A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c ...
A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~
debian
CVE-2020-16301P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16301 [MEDIUM] CVE-2020-16301: ghostscript - A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of...
A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: res
debian
CVE-2025-59801P4LOWCVSS 4.3fixed in ghostscript 10.06.0~dfsg-1 (forky)2025
CVE-2025-59801 [MEDIUM] CVE-2025-59801: ghostscript - In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xp...
In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.06.0~dfsg-1)
sid: resolved (fixed in 10.06.0~dfsg-1)
trixie: open
debian
CVE-2017-7207P4MEDIUMCVSS 5.5fixed in ghostscript 9.20~dfsg-3 (bookworm)2017
CVE-2017-7207 [MEDIUM] CVE-2017-7207: ghostscript - The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 a...
The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.
Scope: local
bookworm: resolved (fixed in 9.20~dfsg-3)
bullseye: resolved (fixed in 9.20~dfsg-3)
forky: resolved (fixed in 9.20~dfsg-3)
sid: resolved (fixed in 9.20~dfsg-
debian