DescriptionArtifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ghostscript (PTS)bullseye (security), bullseye9.53.3~dfsg-7+deb11u7vulnerable
bookworm, bookworm (security)10.0.0~dfsg-11+deb12u4vulnerable
sid, trixie10.03.1~dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs

Notes (ghostpdl-10.03.0)
Ghostscript in Debian not compiled with Tesseract support
Regression (affecting pdf2ps) fix:;a=commit;h=638159c43dbb48425a187d244ec288d252d0ecf4 (ghostpdl-10.03.0)

Search for package or bug name: Reporting problems