Bugzilla – Bug 1213637
VUL-1: CVE-2023-38559: ghostscript, ghostscript-library: out of bounds read devn_pcx_write_rle() could result in DoS
Last modified: 2023-09-19 06:39:00 UTC
CVE-2023-38559 A buffer overflow vulnerability in base/gdevdevn.c:1973 in devn_pcx_write_rle() allows a local attacker to cause a denial of service via a crafted PDF file and outputing it for DEVN device with gs. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-38559 https://bugzilla.redhat.com/show_bug.cgi?id=2224367
All codestreams are affected.
Fix submitted to OBS Printing and forwarded to openSUSE:Factory --------------------------------------------------------------- # osc request accept -m "Security fix CVE-2023-38559 \ bsc#1213637 for ghostscript and ghostscript-mini" 1100802 Result of change request state: ok openSUSE:Factory Forward this submit to it? ([y]/n)y Security fix CVE-2023-38559 bsc#1213637 for ghostscript and ghostscript-mini (forwarded request 1100802 from jsmeix) New request # 1100803 ---------------------------------------------------------------
This is an autogenerated message for OBS integration: This bug (1213637) was mentioned in https://build.opensuse.org/request/show/1100803 Factory / ghostscript
SUSE-SU-2023:3439-1: An update that solves one vulnerability can now be installed. Category: security (low) Bug References: 1213637 CVE References: CVE-2023-38559 Sources used: SUSE Linux Enterprise Software Development Kit 12 SP5 (src): ghostscript-9.52-23.57.1 SUSE Linux Enterprise High Performance Computing 12 SP5 (src): ghostscript-9.52-23.57.1 SUSE Linux Enterprise Server 12 SP5 (src): ghostscript-9.52-23.57.1 SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): ghostscript-9.52-23.57.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:3438-1: An update that solves one vulnerability can now be installed. Category: security (low) Bug References: 1213637 CVE References: CVE-2023-38559 Sources used: openSUSE Leap 15.4 (src): ghostscript-9.52-150000.170.1 openSUSE Leap 15.5 (src): ghostscript-9.52-150000.170.1 Basesystem Module 15-SP4 (src): ghostscript-9.52-150000.170.1 Basesystem Module 15-SP5 (src): ghostscript-9.52-150000.170.1 SUSE Manager Proxy 4.2 (src): ghostscript-9.52-150000.170.1 SUSE Manager Retail Branch Server 4.2 (src): ghostscript-9.52-150000.170.1 SUSE Manager Server 4.2 (src): ghostscript-9.52-150000.170.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.