CVE-2023-28879: Buffer Overflow
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Artifex Ghostscript vulnerability?
The vulnerability ID is CVE-2023-28879.
What is the severity of CVE-2023-28879?
The severity of CVE-2023-28879 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2023-28879?
Artifex Ghostscript version up to 10.01.0, Debian Debian Linux versions 10.0 and 11.0, and certain versions of the Debian ghostscript package.
How can data corruption occur due to CVE-2023-28879?
Data corruption can occur due to a buffer overflow in the PostScript interpreter, potentially affecting BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode.
Where can I find more information about CVE-2023-28879?
You can find more information about CVE-2023-28879 at the following references: [LINK1] [LINK2] [LINK3].