DescriptionArtifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-932-1, DSA-3838-1
Debian Bugs861295

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ghostscript (PTS)bullseye (security), bullseye9.53.3~dfsg-7+deb11u7fixed
bookworm, bookworm (security)10.0.0~dfsg-11+deb12u4fixed
sid, trixie10.03.1~dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs

Notes (duplicate of 697799) (made private)
Full report viewable at:
Fixed by:;a=commit;h=04b37bbce174eed24edec7ad5b920eb93db4d47d
Fixed by:;a=commit;h=4f83478c88c2e05d6e8d79ca4557eb039354d2f3

