5.5
CVE-2023-4042
- EPSS 0.33%
- Veröffentlicht 23.08.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 08:34:17
- Erkennungen
Ghostscript: incomplete fix for cve-2020-16305
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Artifex ≫ Ghostscript Version < 9.51
Redhat ≫ Codeready Linux Builder Version 8.0
Redhat ≫ Codeready Linux Builder For Arm64 Version 8.0_aarch64
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Version 8.0_s390x
Redhat ≫ Codeready Linux Builder For Power Little Endian Version 8.0_ppc64le
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux For Arm 64 Version 8.0_aarch64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0_s390x
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0_ppc64le
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.245 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| RedHat | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://access.redhat.com/errata/RHSA-2023:7053
https://access.redhat.com/security/cve/CVE-2023-4042
https://bugzilla.redhat.com/show_bug.cgi?id=1870257
https://bugzilla.redhat.com/show_bug.cgi?id=2228151