VYPR

rpm package

opensuse/ghostscript&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ghostscript&distro=openSUSE%20Tumbleweed

Vulnerabilities (85)

  • CVE-2024-33871HigJul 3, 2024
    affected < 10.03.1-1.1fixed 10.03.1-1.1

    An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbi

  • CVE-2024-33870MedJul 3, 2024
    affected < 10.03.1-1.1fixed 10.03.1-1.1

    An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will g

  • CVE-2024-33869MedJul 3, 2024
    affected < 10.03.1-1.1fixed 10.03.1-1.1

    An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# ou

  • CVE-2024-29510MedJul 3, 2024
    affected < 10.03.1-1.1fixed 10.03.1-1.1

    Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.

  • CVE-2023-52722MedApr 28, 2024
    affected < 10.03.1-1.1fixed 10.03.1-1.1

    An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.

  • CVE-2023-46751HigDec 6, 2023
    affected < 9.56.1-8.1fixed 9.56.1-8.1

    An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.

  • CVE-2023-43115HigSep 18, 2023
    affected < 9.56.1-6.1fixed 9.56.1-6.1

    In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJ

  • CVE-2023-38559MedAug 1, 2023
    affected < 9.56.1-5.1fixed 9.56.1-5.1

    A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.

  • CVE-2023-36664HigJun 25, 2023
    affected < 9.56.1-4.1fixed 9.56.1-4.1

    Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

  • CVE-2023-28879CriMar 31, 2023
    affected < 9.56.1-2.1fixed 9.56.1-2.1

    In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than fu

  • CVE-2018-25032HigMar 25, 2022
    affected < 10.02.1-1.1fixed 10.02.1-1.1

    zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

  • CVE-2021-3781CriFeb 16, 2022
    affected < 9.54.0-2.2fixed 9.54.0-2.2

    A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript in

  • CVE-2021-45949MedJan 1, 2022
    affected < 9.54.0-3.1fixed 9.54.0-3.1

    Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

  • CVE-2021-45944MedJan 1, 2022
    affected < 9.54.0-3.1fixed 9.54.0-3.1

    Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).

  • CVE-2020-16305MedAug 13, 2020
    affected < 9.56.1-5.1fixed 9.56.1-5.1

    A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-15900CriJul 28, 2020
    affected < 9.54.0-2.2fixed 9.54.0-2.2

    A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32

  • CVE-2020-12268CriApr 27, 2020
    affected < 9.54.0-2.2fixed 9.54.0-2.2

    jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.

  • CVE-2019-10216HigNov 27, 2019
    affected < 9.54.0-2.2fixed 9.54.0-2.2

    In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and acce

  • CVE-2019-14817HigSep 3, 2019
    affected < 9.54.0-2.2fixed 9.54.0-2.2

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and t

  • CVE-2019-14811HigSep 3, 2019
    affected < 9.54.0-2.2fixed 9.54.0-2.2

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then

Page 2 of 5