DescriptionArtifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
ghostscript (PTS)bullseye (security), bullseye9.53.3~dfsg-7+deb11u7vulnerable
bookworm, bookworm (security)10.0.0~dfsg-11+deb12u4vulnerable
sid, trixie10.03.1~dfsg-1fixed

Notes (ghostpdl-10.03.0)
Ghostscript in Debian not compiled with Tesseract support
Regression (affecting pdf2ps) fix:;a=commit;h=638159c43dbb48425a187d244ec288d252d0ecf4 (ghostpdl-10.03.0)

