GhostPCL gsmchunk.c chunk_free_object memory corruption
Published Apr 14, 2022
7.8
HIGHCVSS 3.1
EPSS 0.84%
Description
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.
Affected products
- Vendor n/a Product GhostPCL Defaultunknown
Affected
- 9.55.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | GhostPCL | unknown | Affected
|
No data.
Red Hat Enterprise Linux 6
ghostscript
Not affected
Red Hat Enterprise Linux 7
ghostscript
Not affected
Red Hat Enterprise Linux 8
ghostscript
Not affected
Red Hat Enterprise Linux 8
gimp:flatpak/ghostscript
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ghostscript | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ghostscript | Not affected | n/a |
| Red Hat Enterprise Linux 8 | ghostscript | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gimp:flatpak/ghostscript | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The `ghostscript` package as shipped with Red Hat Enterprise Linux is not affected by this flaw.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-1350 Vendor Advisory
- https://bugs.ghostscript.com/attachment.cgi?id=22323 x_refsource_MISCPermissions RequiredVendor Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=705156 x_refsource_MISCPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2075523 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24672 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1350
- https://vuldb.com/?id.197290 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1350
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-1350 | Vendor Advisory | |
| https://bugs.ghostscript.com/attachment.cgi?id=22323 | x_refsource_MISCPermissions RequiredVendor Advisory | |
| https://bugs.ghostscript.com/show_bug.cgi?id=705156 | x_refsource_MISCPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2075523 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24672 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1350 | ||
| https://vuldb.com/?id.197290 | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-1350 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data