QID 378954

Date Published: 2023-10-30

QID 378954: Ghostscript Memory Corruption Vulnerability

Ghostscript is an interpreter for the PostScript language and PDF files. It is available under either the GNU GPL Affero license or licensed for commercial use from Artifex Software, Inc. It has been under active development for over 30 years and has been ported to several different systems during this time. Ghostscript consists of a PostScript interpreter layer and a graphics library. An exploitable memory corruption vulnerability was discovered in the Ghostscript Postscript interpreter. This vulnerability allows modification of arbitrary memory locations

Affected Versions:
Ghostscript prior to version 9.50
Ghostscript prior to version 9.52
QID Detection logic (Authenticated) It checks for vulnerable version of ghoscript libraries

Successful exploit may allow modification of arbitrary memory locations leading to memory corruption

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Kindly update to the latest version Ghostscript version for additional information on obtaining the fixes.
    Vendor References

    CVEs related to QID 378954

    Software Advisories
    Advisory ID Software Component Link
    Ghostscript URL Logo github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs9530