[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-362 --- ghostscript

ID: oval:org.secpod.oval:def:19500424Date: (C)2024-01-04   (M)2024-02-29
Class: PATCHFamily: unix




In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line

Platform:
Amazon Linux 2023
Product:
ghostscript
libgs
Reference:
ALAS2023-2023-362
CVE-2023-43115
CVE    1
CVE-2023-43115
CPE    2
cpe:/a:ghostscript:libgs
cpe:/a:ghostscript:ghostscript

© SecPod Technologies