CVE-2023-43115: Critical severity Artifex Ghostscript vulnerability

Published Sep 18, 2023
·
Updated

In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).

Other sources

In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated.

References: https://bugs.ghostscript.com/showbug.cgi?id=707051 https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=e59216049cac290fb437a04c4f41ea46826cfba5 https://ghostscript.com/

Red Hat

Affected Software

9 affected componentsFixes available
debian/ghostscript<=9.27~dfsg-2+deb10u5, <=9.27~dfsg-2+deb10u9, <=9.53.3~dfsg-7+deb11u5, <=10.0.0~dfsg-11+deb12u1
9.53.3~dfsg-7+deb11u610.0.0~dfsg-11+deb12u210.02.0~dfsg-2
ubuntu/ghostscript<10.02.0~dfsg-1, <10.02.0
10.02.0~dfsg-110.02.0
ubuntu/ghostscript<9.50~dfsg-5ubuntu4.11
9.50~dfsg-5ubuntu4.11
ubuntu/ghostscript<9.55.0~dfsg1-0ubuntu5.5
9.55.0~dfsg1-0ubuntu5.5
ubuntu/ghostscript<10.0.0~dfsg1-0ubuntu1.4
10.0.0~dfsg1-0ubuntu1.4
ubuntu/ghostscript<10.01.2~dfsg1-0ubuntu2.1
10.01.2~dfsg1-0ubuntu2.1
Artifex Ghostscript<=10.01.2
Fedoraproject Fedora=38
Fedoraproject Fedora=39

Event History

Sep 18, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 28, 2023
Data Sourced
via Red Hat·06:36 AM
DescriptionSeverityAffected Software
Oct 17, 2023
Data Sourced
01:15 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2023-43115?

CVE-2023-43115 is a vulnerability in Artifex Ghostscript through 10.01.2.

2

How severe is CVE-2023-43115?

CVE-2023-43115 has a severity rating of 9.8 (critical).

3

How does CVE-2023-43115 lead to remote code execution?

CVE-2023-43115 allows remote code execution via crafted PostScript documents by switching to the IJS device after SAFER has been activated.

4

How can I check if my version of Ghostscript is affected?

If you are using Artifex Ghostscript version up to and including 10.01.2, your version is affected.

5

Is there a fix for CVE-2023-43115?

Yes, updating Artifex Ghostscript to a version higher than 10.01.2 will fix the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203