Debian Ghostscript vulnerabilities
162 known vulnerabilities affecting debian/ghostscript.
Total CVEs
162
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL16HIGH59MEDIUM65LOW22
Vulnerabilities
Page 7 of 9
CVE-2020-16291P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16291 [MEDIUM] CVE-2020-16291: ghostscript - A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostSc...
A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: resolved (fixed in
debian
CVE-2020-16305P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16305 [MEDIUM] CVE-2020-16305: ghostscript - A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c...
A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid:
debian
CVE-2020-16300P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16300 [MEDIUM] CVE-2020-16300: ghostscript - A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of ...
A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: reso
debian
CVE-2020-16289P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16289 [MEDIUM] CVE-2020-16289: ghostscript - A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Arti...
A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: resolved
debian
CVE-2020-16298P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16298 [MEDIUM] CVE-2020-16298: ghostscript - A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmj...
A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
si
debian
CVE-2020-16290P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16290 [MEDIUM] CVE-2020-16290: ghostscript - A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c o...
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: re
debian
CVE-2020-16288P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16288 [MEDIUM] CVE-2020-16288: ghostscript - A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c ...
A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: r
debian
CVE-2020-16292P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16292 [MEDIUM] CVE-2020-16292: ghostscript - A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c...
A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid:
debian
CVE-2018-16542P4MEDIUMCVSS 5.5fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-16542 [MEDIUM] CVE-2018-16542: ghostscript - In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript ...
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-3)
bullseye: resolved (fixed in 9.22~dfsg-3)
forky: resolved (fixed in 9.22~dfsg-3)
sid: resolved (fixed in 9.22~dfsg-3)
debian
CVE-2020-16308P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16308 [MEDIUM] CVE-2020-16308: ghostscript - A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artif...
A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: resolved
debian
CVE-2020-16309P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16309 [MEDIUM] CVE-2020-16309: ghostscript - A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of...
A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: res
debian
CVE-2020-16294P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16294 [MEDIUM] CVE-2020-16294: ghostscript - A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Ar...
A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: resolv
debian
CVE-2020-16287P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16287 [MEDIUM] CVE-2020-16287: ghostscript - A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c o...
A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: re
debian
CVE-2021-45949P4MEDIUMCVSS 5.5fixed in ghostscript 9.55.0~dfsg-1 (bookworm)2021
CVE-2021-45949 [MEDIUM] CVE-2021-45949: ghostscript - Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sam...
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
Scope: local
bookworm: resolved (fixed in 9.55.0~dfsg-1)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u2)
forky: resolved (fixed in 9.55.0~dfsg-1)
sid: resolved (fixed in 9.55.0~dfsg-1)
trixie: resolved (fixed in 9
debian
CVE-2023-52722P4MEDIUMCVSS 5.5fixed in ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm)2023
CVE-2023-52722 [MEDIUM] CVE-2023-52722: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, whe...
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u4)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u7)
forky: resolved (fixed in 10.02.0~dfsg-1)
sid: resolved (fixed in 10.02.0~dfsg-1)
trixie: r
debian
CVE-2018-19478P4MEDIUMCVSS 5.5fixed in ghostscript 9.26~dfsg-1 (bookworm)2018
CVE-2018-19478 [MEDIUM] CVE-2018-19478: ghostscript - In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an ...
In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.
Scope: local
bookworm: resolved (fixed in 9.26~dfsg-1)
bullseye: resolved (fixed in 9.26~dfsg-1)
forky: resolved (fixed in 9.26~dfsg-1)
sid: resolved (fixed in 9.26~dfsg-1)
trixie: resolved (fixed in 9.26~dfsg-1)
debian
CVE-2020-16306P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16306 [MEDIUM] CVE-2020-16306: ghostscript - A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Softwa...
A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: resolved (f
debian
CVE-2022-2085P4MEDIUMCVSS 5.5fixed in ghostscript 9.56.0~dfsg-1 (bookworm)2022
CVE-2022-2085 [MEDIUM] CVE-2022-2085: ghostscript - A NULL pointer dereference vulnerability was found in Ghostscript, which occurs ...
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64, mem_x_device is used and does not have an init
debian
CVE-2020-16299P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16299 [MEDIUM] CVE-2020-16299: ghostscript - A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev1...
A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
s
debian
CVE-2020-16307P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16307 [MEDIUM] CVE-2020-16307: ghostscript - A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zb...
A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~
debian