← Vulnerability feed

Vulnerability record · CVE-2023-4042 · published 23 August 2023

CVE-2023-4042: Artifex ghostscript out-of-bounds read vulnerability

Artifex · Ghostscript

A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.

5.5 CVSS 3.1 Medium EPSS 0.34% · top 75.7% CWE-125 · Out-of-bounds readCWE-787 · Out-of-bounds write
5.5CVSS 3.1 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-4042 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-8720WebKit memory corruption allows code execution via crafted web contentWebKit contains multiple memory corruption issues in memory handling that are triggered when processing maliciously crafted web content. Successful e…KEVEPSS 1.6%analysed7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed7.8CVE-2017-8291Ghostscript -dSAFER bypass and command execution via type confusionGhostscript through 2017-04-26 contains a type confusion in .rsdparams handling that lets a crafted .eps document bypass the -dSAFER sandbox. A "/Out…KEVEPSS 97%analysed9.9CVE-2021-3781Ghostscript -dSAFER sandbox escape via crafted pipe commandGhostscript's -dSAFER sandbox can be escaped by injecting a specially crafted pipe command, allowing a malicious document to run arbitrary commands a…EPSS 84%analysed9.8CVE-2025-27836Artifex ghostscript classic buffer overflow vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.EPSS 0.59%9.8CVE-2025-27837Artifex ghostscript path traversal vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 charac…EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2023-4042), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.