Impact
Ghostscript versions earlier than 10.08.0 contain a heap‑based0 output adapter. The flaw occurs when JPEG 2000 images declare different subsampling values for their components. The non‑same‑scale sub‑byte‑depth output path allocates a full byte per output column regardless of the image’s bit depth internal chunk‑allocator metadata and allows the attacker to execute arbitrary code with the privileges of the Ghostscript process.
Affected Systems
Artifex Software Ghostscript running any version before 10.08.0. This includes all installations that process PDFs containing JPEG 2000 images. Use cases such as print services, document converters, or web servers are inferred from the description and are not explicitly stated.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3, indicating critical severity. The EPSS score is 0.00486 (less than 1%), and it is not yet listed in CISA’s KEV catalogue. The attack requires an attacker to supply a malicious PDF that Ghostscript will process, typically through local actions or by exploiting a service that runs Ghostscript. Because the flaw is memory corruption in a commonly used who can influence the input that Ghostscript processes.
OpenCVE Enrichment
Debian DSA