VYPR

rpm package

suse/ghostscript&distro=SUSE OpenStack Cloud 9

pkg:rpm/suse/ghostscript&distro=SUSE%20OpenStack%20Cloud%209

Vulnerabilities (4)

  • CVE-2023-36664Jun 25, 2023
    affected < 9.52-23.54.1fixed 9.52-23.54.1

    Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

  • CVE-2023-28879Mar 31, 2023
    affected < 9.52-23.51.1fixed 9.52-23.51.1

    In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than fu

  • CVE-2021-3781Feb 16, 2022
    affected < 9.52-23.42.1fixed 9.52-23.42.1

    A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript in

  • CVE-2020-15900Jul 28, 2020
    affected < 9.52-23.39.1fixed 9.52-23.39.1

    A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32