QID 378954
Date Published: 2023-10-30
QID 378954: Ghostscript Memory Corruption Vulnerability
Ghostscript is an interpreter for the PostScript language and PDF files. It is available under either the GNU GPL Affero license or licensed for commercial use from Artifex Software, Inc. It has been under active development for over 30 years and has been ported to several different systems during this time. Ghostscript consists of a PostScript interpreter layer and a graphics library.
An exploitable memory corruption vulnerability was discovered in the Ghostscript Postscript interpreter. This vulnerability allows modification of arbitrary memory locations
Affected Versions:
Ghostscript prior to version 9.50
Ghostscript prior to version 9.52
QID Detection logic (Authenticated)
It checks for vulnerable version of ghoscript libraries
Successful exploit may allow modification of arbitrary memory locations leading to memory corruption
- Ghostscript -
artifex.com/security-advisories/CVE-2020-15900
CVEs related to QID 378954
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ghostscript |
|