CVE-2023-52722: Medium severity debian/ghostscript vulnerability
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
Other sources
An issue was discovered in Artifex Ghostscript through 10.01.0. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52722?
CVE-2023-52722 is considered a high severity vulnerability due to the potential for arbitrary code execution when SAFER mode is misconfigured.
How do I fix CVE-2023-52722?
To fix CVE-2023-52722, update to Ghostscript version 10.03.1 or later, or apply relevant patches as provided by your distribution.
What software is affected by CVE-2023-52722?
CVE-2023-52722 affects Ghostscript versions prior to 10.03.1, including versions 9.53.3~dfsg-7+deb11u7 and 10.0.0~dfsg-11+deb12u4.
Can CVE-2023-52722 lead to remote exploitation?
Yes, CVE-2023-52722 can potentially allow an attacker to exploit the vulnerability remotely under certain conditions.
Is CVE-2023-52722 related to specific modes in Ghostscript?
CVE-2023-52722 specifically relates to the handling of eexec seeds in Ghostscript when SAFER mode is enabled.