VDB
CVE-2023-38560
CVE-2023-38560
PUBLISHED
Es existieren mehrere Schwachstellen in Ghostscript. Die Fehler sind auf einen Integer Overflow in "pcl/pl/plfont.c:418 in pl_glyph_name" sowie einem Buffer Overflow in "devn_pcx_write_rle()" zurückzuführen. Diese Schwachstellen können mithilfe einer manipulierten PDF-Datei ausgenutzt werden. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um einen Denial of Service Zustand herbeizuführen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.01% · 2.2th percentile
Risk Scores
EPSS Score
0.01%
2.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Xerox FreeFlow Print Server v7 | |
| Amazon | Amazon Linux 2 | |
| Ubuntu | Ubuntu Linux | |
| Red Hat | Red Hat Enterprise Linux <= 9.0 | |
| Red Hat | Red Hat Enterprise Linux | |
| Oracle | Oracle Linux | |
| Xerox | Xerox FreeFlow Print Server v9 | |
| Red Hat | Red Hat Enterprise Linux <= 8.0 | |
| Debian | Debian Linux | |
| Fedora | Fedora Linux | |
| SUSE | SUSE Linux |
Exploit Intelligence
Timeline
- Aug 1, 2023 CVE Published
- Aug 2, 2023 EPSS Score
- Sep 5, 2023 EPSS Score
- Oct 9, 2023 EPSS Score
- Nov 11, 2023 EPSS Score
- Dec 15, 2023 EPSS Score
- Jan 18, 2024 EPSS Score
- Feb 21, 2024 EPSS Score
- Mar 26, 2024 EPSS Score
- Apr 29, 2024 EPSS Score
- Jun 1, 2024 EPSS Score
- Jul 6, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1968.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1968 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2224367 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-d0ef677e6f advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-cba4a3a00f advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00006.html advisory
- https://ubuntu.com/security/notices/USN-6297-1 advisory
- https://alas.aws.amazon.com/ALAS-2023-1801.html advisory
- https://alas.aws.amazon.com/AL2/ALAS-2023-2204.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-August/016027.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-August/016028.html advisory
- https://access.redhat.com/errata/RHSA-2023:6544 advisory
- https://access.redhat.com/errata/RHSA-2023:7053 advisory
- https://linux.oracle.com/errata/ELSA-2023-6732.html advisory
- https://security.business.xerox.com/wp-content/uploads/2024/03/Xerox-Security-Bulletin-XRX24-005-Xerox-FreeFlow%C2%AE-Print-Server-v9_Feb-2024.pdf advisory
- https://security.business.xerox.com/wp-content/uploads/2024/03/Xerox%C2%AE-Security-Bulletin-XRX24-004-Xerox%C2%AE-FreeFlow%C2%AE-Print-Server-v7.pdf advisory