CVE-2023-38559

Name
CVE-2023-38559
Description
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=d81b82c70bc1
MISC https://access.redhat.com/security/cve/CVE-2023-38559
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2224367
MISC https://bugs.ghostscript.com/show_bug.cgi?id=706897
MISC https://lists.debian.org/debian-lts-announce/2023/08/msg00006.html
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QH7ERAYSSXEYDWWY7LOV7CA5MIDZN3Z6/
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GBV6BTUREXM6DB3OGHGLMWGAZ3I45TXE/
https://access.redhat.com/errata/RHSA-2023:6544
https://access.redhat.com/errata/RHSA-2023:7053

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:artifex:ghostscript:-:*:*:*:*:*:*:* ghostscript == None == -
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:* ghostscript >= None < 10.02.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ghostscript 3.17-main 10.01.2-r0 Cameron Banta <cbanta@gmail.com> possibly vulnerable
ghostscript 3.16-main 9.56.1-r2 Cameron Banta <cbanta@gmail.com> possibly vulnerable