CVE-2023-38560: Ghostscript: integer overflow in pcl/pl/plfont.c:418 in pl_glyph_name
An integer overflow flaw was found in pcl/pl/plfont.c:418 in plglyphname in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
Other sources
An Integer overflow in pcl/pl/plfont.c:418 in plglyphname allows a local attacker to cause a denial of service via a rafted PCL file and tranforming it to PDF format
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-38560.
Where is the vulnerability located?
The vulnerability is located in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript.
What is the impact of this vulnerability?
This vulnerability may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
What software is affected by this vulnerability?
Artifex Ghostscript is affected by this vulnerability.
How severe is this vulnerability?
The severity of this vulnerability is medium, with a CVSS score of 5.5.