Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28879

Опубликовано: 31 мар. 2023
Источник: redhat
CVSS3: 8.4
EPSS Средний

Описание

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ghostscriptOut of support scope
Red Hat Enterprise Linux 7ghostscriptOut of support scope
Red Hat Enterprise Linux 8gimp:flatpak/ghostscriptWill not fix
Red Hat Enterprise Linux 8ghostscriptFixedRHSA-2023:705314.11.2023
Red Hat Enterprise Linux 9ghostscriptFixedRHSA-2023:654407.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2184585ghostscript: buffer overflow in base/sbcp.c leading to data corruption

EPSS

Процентиль: 97%
0.3164
Средний

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

CVSS3: 9.8
nvd
около 2 лет назад

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

CVSS3: 9.8
debian
около 2 лет назад

In Artifex Ghostscript through 10.01.0, there is a buffer overflow lea ...

suse-cvrf
около 2 лет назад

Security update for ghostscript

suse-cvrf
около 2 лет назад

Security update for ghostscript

EPSS

Процентиль: 97%
0.3164
Средний

8.4 High

CVSS3