Medium severity5.5NVD Advisory· Published Aug 1, 2023· Updated Jun 17, 2026
CVE-2023-38560
CVE-2023-38560
Description
An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:artifex:ghostscript:-:*:*:*:*:*:*:*
cpe:/o:redhat:enterprise_linux:6+ 3 more
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- cpe:/o:redhat:enterprise_linux:8
- cpe:/o:redhat:enterprise_linux:9
- osv-coords8 versionspkg:apk/chainguard/ghostscriptpkg:apk/chainguard/ghostscript-dbgpkg:apk/chainguard/ghostscript-devpkg:apk/wolfi/ghostscriptpkg:apk/wolfi/ghostscript-dbgpkg:apk/wolfi/ghostscript-docpkg:apk/wolfi/ghostscript-devpkg:apk/chainguard/ghostscript-doc
< 10.02.0-r0+ 7 more
- (no CPE)range: < 10.02.0-r0
- (no CPE)range: < 10.02.0-r0
- (no CPE)range: < 10.02.0-r0
- (no CPE)range: < 10.02.0-r0
- (no CPE)range: < 10.02.0-r0
- (no CPE)range: < 10.02.0-r0
- (no CPE)range: < 10.02.0-r0
- (no CPE)range: < 10.02.0-r0
Patches
Vulnerability mechanics
References
4- git.ghostscript.comnvdMailing ListPatch
- access.redhat.com/security/cve/CVE-2023-38560nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- bugs.ghostscript.com/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.