CVE-2023-4042: Ghostscript: incomplete fix for cve-2020-16305
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
Other sources
The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
References:
https://access.redhat.com/errata/RHSA-2021:1852 https://access.redhat.com/security/cve/CVE-2020-16305
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in ghostscript?
The vulnerability ID for this flaw in ghostscript is CVE-2023-4042.
What is the severity of CVE-2023-4042?
The severity of CVE-2023-4042 is medium with a CVSS score of 5.5.
Which version of ghostscript is affected by CVE-2023-4042?
The version affected by CVE-2023-4042 is up to exclusive 9.51.
What is the affected software for CVE-2023-4042?
The affected software for CVE-2023-4042 is ghostscript package as shipped with Red Hat Enterprise Linux 8.
How can I fix CVE-2023-4042?
To fix CVE-2023-4042, update to ghostscript version 9.51 or later.