Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28879

Опубликовано: 31 мар. 2023
Источник: nvd
CVSS3: 9.8
EPSS Средний

Описание

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
Версия до 10.01.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.3164
Средний

9.8 Critical

CVSS3

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

CVSS3: 8.4
redhat
около 2 лет назад

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

CVSS3: 9.8
debian
около 2 лет назад

In Artifex Ghostscript through 10.01.0, there is a buffer overflow lea ...

suse-cvrf
около 2 лет назад

Security update for ghostscript

suse-cvrf
около 2 лет назад

Security update for ghostscript

EPSS

Процентиль: 97%
0.3164
Средний

9.8 Critical

CVSS3

Дефекты

CWE-787
CWE-787