#VU85892 Integer overflow in Ghostscript - CVE-2023-38560
Published: January 30, 2024
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to integer overflow within the pl_glyph_name() function in pcl/pl/plfont.c when converting PCL files to PDF format. A remote attacker can pass a specially crafted PLC file to the application, trigger an integer overflow and perform a denial of service (DoS) attack.