Lucene search

K
redosRedosROS-20230907-01
HistorySep 07, 2023 - 12:00 a.m.

ROS-20230907-01

2023-09-0700:00:00
redos.red-soft.ru
12
ghostscript
buffer overflow
devn_pcx_write_rle
denial of service
pdf
devn
unix

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

20.3%

Ghostscript document processing toolkit vulnerability is related to a buffer overflow error in base / gdevdevn.c: 1973 in devn_pcx_write_rle().
buffer overflow in base / gdevdevn.c: 1973 in devn_pcx_write_rle(). Exploitation of the vulnerability could allow
an attacker acting remotely to cause a denial of service by outputting a crafted PDF for a
DEVN device using gs.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64ghostscript<= 9.52-6UNKNOWN

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

20.3%