PT-2023-6796 · Unknown+9 · Ghostscript+9

Michael Kaplan

·

Published

2023-07-17

·

Updated

2025-01-28

·

CVE-2023-38559

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ghostscript (affected versions not specified)
Description The issue is related to a buffer overflow flaw in the devn pcx write rle() function of the Ghostscript software, specifically in the base/gdevdevn.c component. This flaw may allow a local attacker to cause a denial of service by outputting a specially crafted PDF file for a DEVN device using Ghostscript.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2023:6544
ALSA-2023:7053
ALT-PU-2024-13477
ALT-PU-2024-14136
ALT-PU-2024-14302
BDU:2023-07662
CESA-2023_7053
CVE-2023-38559
DLA-3519-1
MGASA-2023-0260
OESA-2023-1604
OESA-2023-1605
OESA-2023-1606
OESA-2023-1607
OESA-2023-1608
OPENSUSE-SU-2023_3438-1
OPENSUSE-SU-2024:13081-1
RHSA-2023:6544
RHSA-2023:7053
RHSA-2023_6544
RHSA-2023_7053
ROSA-SA-2025-2622
SUSE-SU-2023:3438-1
SUSE-SU-2023:3439-1
SUSE-SU-2023_3438-1
SUSE-SU-2023_3439-1
USN-6297-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ghostscript
Linuxmint
Red Hat
Red Os
Suse
Ubuntu