Debian Ghostscript vulnerabilities
162 known vulnerabilities affecting debian/ghostscript.
Total CVEs
162
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL16HIGH59MEDIUM65LOW22
Vulnerabilities
Page 8 of 9
CVE-2020-16295P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16295 [MEDIUM] CVE-2020-16295: ghostscript - A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj....
A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid:
debian
CVE-2020-16310P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16310 [MEDIUM] CVE-2020-16310: ghostscript - A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of ...
A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: reso
debian
CVE-2020-16293P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-16293 [MEDIUM] CVE-2020-16293: ghostscript - A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_i...
A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
fo
debian
CVE-2018-16541P4MEDIUMCVSS 5.5fixed in ghostscript 9.22~dfsg-3 (bookworm)2018
CVE-2018-16541 [MEDIUM] CVE-2018-16541: ghostscript - In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript ...
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-3)
bullseye: resolved (fixed in 9.22~dfsg-3)
forky: resolved (fixed in 9.22~dfsg-3)
sid: resolved (fixed in 9.22~dfsg-3)
trixie: resolved (fi
debian
CVE-2020-14373P4MEDIUMCVSS 5.5fixed in ghostscript 9.26~dfsg-1 (bookworm)2020
CVE-2020-14373 [MEDIUM] CVE-2020-14373: ghostscript - A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript...
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 9.26~dfsg-1)
bullseye: resolved (fixed in 9.26~dfsg-1)
forky: resolved (fixed in 9.26~dfsg-1)
sid: resolved (fixed in 9.26~dfsg-1)
trixie: resol
debian
CVE-2017-5951P4MEDIUMCVSS 5.5fixed in ghostscript 9.20~dfsg-3.1 (bookworm)2017
CVE-2017-5951 [MEDIUM] CVE-2017-5951: ghostscript - The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. ...
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 9.20~dfsg-3.1)
bullseye: resolved (fixed in 9.20~dfsg-3.1)
forky: resolved (fixed in 9.20~dfsg-3.1)
sid
debian
CVE-2021-45944P4MEDIUMCVSS 5.5fixed in ghostscript 9.54.0~dfsg-5 (bookworm)2021
CVE-2021-45944 [MEDIUM] CVE-2021-45944: ghostscript - Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sa...
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
Scope: local
bookworm: resolved (fixed in 9.54.0~dfsg-5)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u2)
forky: resolved (fixed in 9.54.0~dfsg-5)
sid: resolved (fixed in 9.54.0~dfsg-5)
trixie: resolved (fixed in 9.54.0~dfsg-5
debian
CVE-2017-8908P4LOWCVSS 5.5fixed in ghostscript 9.22~dfsg-1 (bookworm)2017
CVE-2017-8908 [MEDIUM] CVE-2017-8908: ghostscript - The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote...
The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.
Scope: local
bookworm: resolved (fixed in 9.22~dfsg-1)
bullseye: resolved (fixed in 9.22~dfsg-1)
forky: resolved (fixed in 9.22~dfsg-1)
sid: resolved (fixed in 9.22~dfsg-1)
trixie: resolve
debian
CVE-2016-10219P4MEDIUMCVSS 5.5fixed in ghostscript 9.20~dfsg-3.1 (bookworm)2016
CVE-2016-10219 [MEDIUM] CVE-2016-10219: ghostscript - The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9....
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 9.20~dfsg-3.1)
bullseye: resolved (fixed in 9.20~dfsg-3.1)
forky: resolved (fixed in 9.20~dfsg-3.1)
sid: resolved (fixe
debian
CVE-2016-10220P4MEDIUMCVSS 5.5fixed in ghostscript 9.20~dfsg-3.1 (bookworm)2016
CVE-2016-10220 [MEDIUM] CVE-2016-10220: ghostscript - The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc....
The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.
Scope: local
bookworm: resolved (fixed in 9.20~dfsg-3.1)
bullseye: resolved (fixed in 9.20~d
debian
CVE-2023-38559P4MEDIUMCVSS 5.5fixed in ghostscript 10.0.0~dfsg-11+deb12u2 (bookworm)2023
CVE-2023-38559 [MEDIUM] CVE-2023-38559: ghostscript - A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle()...
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u2)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u6)
forky: resolved (fi
debian
CVE-2024-46955P4MEDIUMCVSS 5.5fixed in ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm)2024
CVE-2024-46955 [MEDIUM] CVE-2024-46955: ghostscript - An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. T...
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u6)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u9)
forky: resolved (fixed in 10.04.0~dfsg-1)
sid: resolved (fixed in 10.04.0~dfsg-1)
trixie: r
debian
CVE-2025-46646P4LOWCVSS 7.8fixed in ghostscript 10.05.0~dfsg-1 (forky)2025
CVE-2025-46646 [HIGH] CVE-2025-46646: ghostscript - In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles ...
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 10.05.0~dfsg-1)
sid: resolved (fixed in 10.05.0~dfsg-1)
trixie: resolved (fixed in 10.05.0~dfsg-1)
debian
CVE-2025-7462P4MEDIUMCVSS 5.3fixed in ghostscript 10.0.0~dfsg-11+deb12u8 (bookworm)2025
CVE-2025-7462 [MEDIUM] CVE-2025-7462: ghostscript - A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902b...
A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. This affects the function pdf_ferror of the file devices/vector/gdevpdf.c of the component New Output File Open Error Handler. The manipulation leads to null pointer dereference. It is possible to initiate the attack remotely. The
debian
CVE-2010-4820P4HIGHCVSS 7.2fixed in ghostscript 8.71~dfsg2-6.1 (bookworm)2010
CVE-2010-4820 [HIGH] CVE-2010-4820: ghostscript - Untrusted search path vulnerability in Ghostscript 8.62 allows local users to ex...
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.
Scope: local
bookworm: resolved (fixed in 8.71~dfsg2-6.1)
bullseye: resolved (fixed in 8.71~dfsg2-6.1)
forky: resol
debian
CVE-2016-10217P4MEDIUMCVSS 5.5fixed in ghostscript 9.20~dfsg-3.1 (bookworm)2016
CVE-2016-10217 [MEDIUM] CVE-2016-10217: ghostscript - The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript ...
The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file that is mishandled in the color management module.
Scope: local
bookworm: resolved (fixed in 9.20~dfsg-3.1)
bullseye: resolved (fixed in 9.20~dfsg-3.1)
forky: resolve
debian
CVE-2020-21710P4MEDIUMCVSS 5.5fixed in ghostscript 9.51~dfsg-1 (bookworm)2020
CVE-2020-21710 [MEDIUM] CVE-2020-21710: ghostscript - A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Sof...
A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file.
Scope: local
bookworm: resolved (fixed in 9.51~dfsg-1)
bullseye: resolved (fixed in 9.51~dfsg-1)
forky: resolved (fixed in 9.51~dfsg-1)
sid: resolved (fixed in 9.51~dfsg-1)
debian
CVE-2010-4054P4LOWCVSS 4.3fixed in ghostscript 8.71~dfsg-1 (bookworm)2010
CVE-2010-4054 [MEDIUM] CVE-2010-4054: ghostscript - The gs_type2_interpret function in Ghostscript allows remote attackers to cause ...
The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.
Scope: local
bookworm: resolved (fixed in 8.71~dfsg-1)
bullseye: resolved (fixed in 8.71~dfsg-1)
forky: resolved (fixed in 8.71~dfsg-1)
sid: re
debian
CVE-2023-38560P4LOWCVSS 5.5fixed in ghostscript 10.02.0~dfsg-1 (forky)2023
CVE-2023-38560 [MEDIUM] CVE-2023-38560: ghostscript - An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in gh...
An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.02.0~dfsg-1)
sid: resolved (fixed in 10.02.0~dfsg-1)
trixie: resolved (fixed in 1
debian
CVE-2007-2721P4MEDIUMCVSS 4.3fixed in ghostscript 8.61.dfsg.1~svn8187-1.1 (bookworm)2007
CVE-2007-2721 [MEDIUM] CVE-2007-2721: ghostscript - The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 libra...
The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.
Scope: local
bookworm: resolved (fixed in 8.61.dfsg.1~svn8187-1.1)
bul
debian