<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:55:35 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6544 — Moderate: ghostscript security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6544</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: ghostscript, AlmaLinux:9: ghostscript-doc, AlmaLinux:9: ghostscript-tools-dvipdf, AlmaLinux:9: ghostscript-tools-fonts, AlmaLinux:9: ghostscript-tools-printing, AlmaLinux:9: ghostscript-x11, AlmaLinux:9: libgs, AlmaLinux:9: libgs-devel&lt;/p&gt;
&lt;p&gt;The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ghostscript: buffer overflow in base/sbcp.c leading to data corruption (CVE-2023-28879)
* ghostscript: Out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in DoS (CVE-2023-38559)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: ghostscript, AlmaLinux:9: ghostscript-doc, AlmaLinux:9: ghostscript-tools-dvipdf, AlmaLinux:9: ghostscript-tools-fonts, AlmaLinux:9: ghostscript-tools-printing, AlmaLinux:9: ghostscript-x11, AlmaLinux:9: libgs, AlmaLinux:9: libgs-devel&lt;/p&gt;
&lt;p&gt;The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ghostscript: buffer overflow in base/sbcp.c leading to data corruption (CVE-2023-28879)
* ghostscript: Out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in DoS (CVE-2023-38559)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6544</guid>
    </item>
    <item>
      <title>bdu:2023-02055</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-02055</link>
      <description>bdu:2023-02055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-02055</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-28879 — CVE-2023-28879 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-28879</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-28879</guid>
    </item>
    <item>
      <title>EUVD-2026-217753</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217753</link>
      <description>EUVD-2026-217753</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217753</guid>
    </item>
    <item>
      <title>fkie_cve-2023-28879</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28879</link>
      <description>&lt;p&gt;In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-28879</guid>
    </item>
    <item>
      <title>GHSA-6mcj-frmm-wmr5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6mcj-frmm-wmr5</link>
      <description>&lt;p&gt;In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6mcj-frmm-wmr5</guid>
    </item>
    <item>
      <title>gsd-2023-28879</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-28879</link>
      <description>gsd-2023-28879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-28879</guid>
    </item>
    <item>
      <title>OESA-2023-1604 — ghostscript security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1604</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ghostscript&lt;/p&gt;
&lt;p&gt;Ghostscript is an interpreter for PostScript™ and Portable Document Format (PDF) files. Ghostscript consists of a PostScript interpreter layer, and a graphics library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.(CVE-2023-28879)&#13;
&#13;
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).(CVE-2023-36664)&#13;
&#13;
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.(CVE-2023-38559)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ghostscript&lt;/p&gt;
&lt;p&gt;Ghostscript is an interpreter for PostScript™ and Portable Document Format (PDF) files. Ghostscript consists of a PostScript interpreter layer, and a graphics library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.(CVE-2023-28879)&#13;
&#13;
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).(CVE-2023-36664)&#13;
&#13;
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.(CVE-2023-38559)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1604</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12853-1 — ghostscript-9.56.1-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12853-1</link>
      <description>&lt;p&gt;ghostscript-9.56.1-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ghostscript-9.56.1-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12853-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:1797-1 — Security update for ghostscript</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:1797-1</link>
      <description>&lt;p&gt;Security update for ghostscript&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ghostscript&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:1797-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-28879</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28879</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ghostscript, Ubuntu:18.04:LTS: ghostscript, Ubuntu:20.04:LTS: ghostscript, Ubuntu:22.04:LTS: ghostscript&lt;/p&gt;
&lt;p&gt;In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ghostscript, Ubuntu:18.04:LTS: ghostscript, Ubuntu:20.04:LTS: ghostscript, Ubuntu:22.04:LTS: ghostscript&lt;/p&gt;
&lt;p&gt;In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28879</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0827 — Ghostscript: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0827</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ghostscript ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ghostscript ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0827</guid>
    </item>
  </channel>
</rss>
