Input validation error in Ghostscript - CVE-2023-52722

 

Input validation error in Ghostscript - CVE-2023-52722

Published: May 10, 2024


Vulnerability identifier: #VU89349
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-52722
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Ghostscript
Oracle Solaris
Amazon Linux AMI
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
libgs-dev (Ubuntu package)
ghostscript-doc (Ubuntu package)
ghostscript-x (Ubuntu package)
libgs9-common (Ubuntu package)
ghostscript (Ubuntu package)
libgs9 (Ubuntu package)
ghostscript-debuginfo
ghostscript
ghostscript-devel
ghostscript-debugsource
ghostscript-x11
ghostscript-x11-debuginfo
ghostscript (Debian package)
ghostscript-help
ghostscript-tools-dvipdf
libgs10-common (Ubuntu package)
libgs10 (Ubuntu package)
libgs-common (Ubuntu package)
app-text/ghostscript-gpl

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in psi/zmisc1.c. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.


How to mitigate CVE-2023-52722

Install updates from vendor's website.

Sources