Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2023-38560

Published: 1 August 2023

An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.

Notes

AuthorNote
Priority reason:
PCL is not built by default, some releases don't include pcl/ dir
rodrigo-zaiden
by default, PCL is not built in Ubuntu, this happens with
the usage of the build option --without-pcl. most releases don't package
pcl/ dir.
PCL is not built or packed due to a build issue with
system-shared libjpeg. more in https://bugs.ghostscript.com/show_bug.cgi?id=696654

Priority

Negligible

Cvss 3 Severity Score

5.5

Score breakdown

Status

Package Release Status
ghostscript
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(code not present)
focal Ignored
(code not built)
jammy Not vulnerable
(code not present)
lunar Ignored
(end of life, was ignored [code not built])
trusty Ignored
(end of standard support)
upstream
Released (10.02.0rc1)
xenial Not vulnerable
(code not present)
Patches:
upstream: https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=b7eb1d0174cb25a0cd44a1c0706c2ed73fc95bef

Severity score breakdown

Parameter Value
Base score 5.5
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H