CVE-2023-38559: Ghostscript: 1973 in devn_pcx_write_rle could result in dos
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devnpcxwriterle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
Other sources
A buffer overflow vulnerability in base/gdevdevn.c:1973 in devnpcxwriterle() allows a local attacker to cause a denial of service via a crafted PDF file and outputing it for DEVN device with gs.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/ghostscriptto a version that resolves this vulnerability.Fixed in 9.26~dfsg+0-0ubuntu0.18.04.18+ - Upgrade
Upgrade
ubuntu/ghostscriptto a version that resolves this vulnerability.Fixed in 9.50~dfsg-5ubuntu4.9 - Upgrade
Upgrade
ubuntu/ghostscriptto a version that resolves this vulnerability.Fixed in 9.55.0~dfsg1-0ubuntu5.4 - Upgrade
Upgrade
ubuntu/ghostscriptto a version that resolves this vulnerability.Fixed in 10.0.0~dfsg1-0ubuntu1.3 - Upgrade
Upgrade
ubuntu/ghostscriptto a version that resolves this vulnerability.Fixed in 9.26~dfsg+0-0ubuntu0.16.04.14+ - Upgrade
Upgrade
ubuntu/ghostscriptto a version that resolves this vulnerability.Fixed in 10.01.2~dfsg1-0ubuntu2 - Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 9.27~dfsg-2+deb10u9Fixed in 9.53.3~dfsg-7+deb11u6Fixed in 10.0.0~dfsg-11+deb12u3Fixed in 10.02.1~dfsg-3
Event History
Frequently Asked Questions
What is the vulnerability ID of this buffer overflow flaw?
The vulnerability ID of this buffer overflow flaw is CVE-2023-38559.
Where is the buffer overflow flaw located?
The buffer overflow flaw is located in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript.
What is the impact of this buffer overflow flaw?
This buffer overflow flaw may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
Which software is affected by this buffer overflow flaw?
The Artifex Ghostscript software and Redhat Enterprise Linux 8.0 and 9.0 are affected by this buffer overflow flaw.
What is the severity of this buffer overflow flaw?
The severity of this buffer overflow flaw is medium with a score of 5.5.