CVE-2023-28879: Artifex Ghostscript
Critical severity, CVSS 9.8. EPSS: 6.3% chance of exploitation in the next 30 days.
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
Affected products
- Artifex Ghostscript: before 10.01.0 (fixed in 10.01.0)
- Debian Debian Linux: version 10.0 only; version 11.0 only
Published 2023-03-31. Last modified 2026-06-17.