yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2023-38560
Component Overview
Vulnerability Overview
Name
CVE-2023-38560
Source
NVD (
link
)
Debian (
link
)
Description
An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
CWEs
CWE-190
CWE-190
Published Date
Aug 1, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://access.redhat.com/security/cve/CVE-2023-38560
Third Party Advisory
https://bugs.ghostscript.com/show_bug.cgi?id=706898
Permissions Required
https://bugzilla.redhat.com/show_bug.cgi?id=2224368
Issue Tracking
https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=b7eb1d0174c
Mailing List
https://access.redhat.com/security/cve/CVE-2023-38560
Third Party Advisory
https://bugs.ghostscript.com/show_bug.cgi?id=706898
Permissions Required
https://bugzilla.redhat.com/show_bug.cgi?id=2224368
Issue Tracking
https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=b7eb1d0174c
Mailing List
Analysis
#
Affected Component
Analysis
ghostscript
False Positive
Vulnerability Ratings
#
5.5
CVSSv31
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ghostscript
buildroot
2025.02.x
10.07.0
Not Affected
ghostscript
buildroot
master
10.07.0
Not Affected
ghostscript
yocto
kirkstone
9.55.0
Not Affected
ghostscript
yocto
master
10.07.1
False Positive