Bug 2278775 (CVE-2023-52722) - CVE-2023-52722 ghostscript: eexec seeds other than the Type 1 standard are allowed while using SAFER mode
Summary: CVE-2023-52722 ghostscript: eexec seeds other than the Type 1 standard are al...
Keywords:
Status: NEW
Alias: CVE-2023-52722
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2278777
Blocks: 2278776
TreeView+ depends on / blocked
 
Reported: 2024-05-03 02:24 UTC by Robb Gatica
Modified: 2024-08-01 13:33 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Robb Gatica 2024-05-03 02:24:55 UTC
An issue was discovered in Artifex Ghostscript through 10.01.0. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.

https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=afd7188f74918cb51b5fb89f52b54eb16e8acfd1

Comment 1 Robb Gatica 2024-05-03 02:27:56 UTC
Created ghostscript tracking bugs for this issue:

Affects: fedora-all [bug 2278777]


Note You need to log in before you can comment on or make changes to this bug.