In Artifex Ghostscript through 10.01.2, gdevijs.c in...
High severity
Unreviewed
Published
Sep 18, 2023
to the GitHub Advisory Database
•
Updated Feb 22, 2024
Description
Published by the National Vulnerability Database
Sep 18, 2023
Published to the GitHub Advisory Database
Sep 18, 2023
Last updated
Feb 22, 2024
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).
References