yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-38559
Component Overview
Vulnerability Overview
Name
CVE-2023-38559
Source
NVD (
link
)
Debian (
link
)
Description
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
CWEs
CWE-125
CWE-120
Published Date
Aug 1, 2023
Updated Date
Jun 23, 2026
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2023:6544
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7053
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-38559
Third Party Advisory
https://bugs.ghostscript.com/show_bug.cgi?id=706897
Permissions Required
https://bugzilla.redhat.com/show_bug.cgi?id=2224367
Issue Tracking
https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=d81b82c70bc1
Mailing List
https://access.redhat.com/errata/RHSA-2023:6544
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7053
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-38559
Third Party Advisory
https://bugs.ghostscript.com/show_bug.cgi?id=706897
Permissions Required
https://bugzilla.redhat.com/show_bug.cgi?id=2224367
Issue Tracking
https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=d81b82c70bc1
Mailing List
Analysis
#
Affected Component
Analysis
ghostscript
Patched
Vulnerability Ratings
#
5.5
CVSSv31
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ghostscript
buildroot
2025.02.x
10.07.0
Not Affected
ghostscript
buildroot
master
10.07.0
Not Affected
ghostscript
yocto
master
10.07.1
Not Affected
ghostscript
yocto
scarthgap
10.05.1
False Positive
Resolved with patches
#
ghostscript (yocto:kirkstone)
#
Title
Author
Resolve
1
Bug 706897: Copy pcx buffer overrun fix from
Chris Liddell <chris.liddell@artifex.com>
CVE-2023-38559