Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-38559
HistoryAug 01, 2023 - 12:00 a.m.

CVE-2023-38559

2023-08-0100:00:00
ubuntu.com
ubuntu.com
11
buffer overflow
ghostscript
denial of service
crafted pdf
devn device

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

20.3%

A buffer overflow flaw was found in base/gdevdevn.c:1973 in
devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker
to cause a denial of service via outputting a crafted PDF file for a DEVN
device with gs.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchghostscript< 9.26~dfsg+0-0ubuntu0.18.04.18+esm1UNKNOWN
ubuntu20.04noarchghostscript< 9.50~dfsg-5ubuntu4.9UNKNOWN
ubuntu22.04noarchghostscript< 9.55.0~dfsg1-0ubuntu5.4UNKNOWN
ubuntu23.04noarchghostscript< 10.0.0~dfsg1-0ubuntu1.3UNKNOWN
ubuntu23.10noarchghostscript< 10.01.2~dfsg1-0ubuntu2UNKNOWN
ubuntu16.04noarchghostscript< 9.26~dfsg+0-0ubuntu0.16.04.14+esm6UNKNOWN

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

20.3%