{"id":"MGASA-2023-0290","summary":"Updated ghostscript packages fix security vulnerability","details":"The updated packages fix a security vulnerability:\n\nIn Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead\nto remote code execution via crafted PostScript documents because they\ncan switch to the IJS device, or change the IjsServer parameter, after\nSAFER has been activated. (CVE-2023-43115)\n","modified":"2026-04-16T04:43:19.719398056Z","published":"2023-10-19T16:11:51Z","upstream":["CVE-2023-43115"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0290.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32400"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PG5AQV7JOL5TAU76FWPJCMSKO5DREKV5/"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6433-1"}],"affected":[{"package":{"name":"ghostscript","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/ghostscript?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.53.3-2.7.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0290.json"}},{"package":{"name":"ghostscript","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/ghostscript?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.00.0-6.3.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0290.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}