CVE-2023-28879
Last modified
CVE-2023-28879 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. EPSS estimates a 6.34% chance of exploitation in the next 30 days.
Description
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Ghostscript | < 10.01.0 |
| Debian | Debian Linux | 10.0 |
| Debian | Debian Linux | 11.0 |
References
- https://bugs.ghostscript.com/show_bug.cgi?id=706494Exploit, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00003.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5383Third Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=706494Exploit, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00003.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5383Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-28879?
How severe is CVE-2023-28879?
How do I fix CVE-2023-28879?
Are you affected by CVE-2023-28879?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
