CVE-2023-43115
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).
- Affected products
- Alt Linux, Almalinux, Artifex Ghostscript, Astra Linux, Linuxmint, Red Hat, Suse, Ubuntu
- Artifex Ghostscript
- ≤ 10.01.2
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 4.7% (91th percentile)
- NVD status
- Modified
- Published
- 2023-09-18
CVE-2023-43115 at NVD
1 known exploit for CVE-2023-43115
Proof-of-concept code and exploit modules indexed by Sploitus