In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
History

Fri, 14 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-14T19:29:52.451Z

Reserved: 2023-03-27T00:00:00.000Z

Link: CVE-2023-28879

cve-icon Vulnrichment

Updated: 2024-08-02T13:51:38.670Z

cve-icon NVD

Status : Modified

Published: 2023-03-31T17:15:06.697

Modified: 2025-02-14T20:15:33.373

Link: CVE-2023-28879

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-03-31T00:00:00Z

Links: CVE-2023-28879 - Bugzilla