Back

HIGH

ghostscript: dangling pointer in gdev_prn_open_printer_seekable()

Published Dec 6, 2023

Description

An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.

Affected products

Remediation

Red Hat statement

The discovered vulnerability in the function gdev_prn_open_printer_seekable() within Artifex Ghostscript, poses a moderate severity threat due to its potential to cause a denial-of-service (DoS) condition. Exploiting this flaw involves manipulating a dangling pointer, which can lead to crashing the application. While the impact is limited to crashing the application, the exploit requires remote access, which elevates the risk compared to local-only vulnerabilities.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 6, 2023
Updated Aug 2, 2024
Reserved Oct 26, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 6, 2023