CVE-2021-3781

A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
artifexghostscript
9.50
artifexghostscript
9.52
artifexghostscript
9.53.3
artifexghostscript
9.54.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ghostscript
bookworm
10.0.0~dfsg-11+deb12u4
fixed
bookworm (security)
10.0.0~dfsg-11+deb12u5
fixed
bullseye
9.53.3~dfsg-7+deb11u7
fixed
bullseye (security)
9.53.3~dfsg-7+deb11u8
fixed
buster
not-affected
sid
10.04.0~dfsg-1
fixed
stretch
not-affected
trixie
10.04.0~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ghostscript
bionic
not-affected
focal
Fixed 9.50~dfsg-5ubuntu4.3
released
hirsute
Fixed 9.53.3~dfsg-7ubuntu0.1
released
impish
Fixed 9.54.0~dfsg1-0ubuntu2
released
jammy
Fixed 9.54.0~dfsg1-0ubuntu2
released
trusty
dne
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
ghostscript
suse enterprise desktop 15 SP2
9.52-155.1
fixed
suse enterprise desktop 15 SP3
9.52-155.1
fixed
suse enterprise desktop 15 SP4
9.52-155.1
fixed
suse enterprise desktop 15 SP5
9.52-155.1
fixed
suse enterprise desktop 15 SP6
9.52-155.1
fixed
suse enterprise desktop 15 SP7
9.52-155.1
fixed
suse enterprise sap 12 SP3
9.52-23.42.1
fixed
suse enterprise sap 12 SP4
9.52-23.42.1
fixed
suse enterprise sap 12 SP5
9.52-23.42.1
fixed
suse enterprise sap 15
9.52-155.1
fixed
suse enterprise sap 15 SP1
9.52-155.1
fixed
suse enterprise sap 15 SP2
9.52-155.1
fixed
suse enterprise sap 15 SP3
9.52-155.1
fixed
suse enterprise sap 15 SP4
9.52-155.1
fixed
suse enterprise sap 15 SP5
9.52-155.1
fixed
suse enterprise sap 15 SP6
9.52-155.1
fixed
suse enterprise sap 15 SP7
9.52-155.1
fixed
suse enterprise server 12 SP2
9.52-23.42.1
fixed
suse enterprise server 12 SP3
9.52-23.42.1
fixed
suse enterprise server 12 SP4
9.52-23.42.1
fixed
suse enterprise server 12 SP5
9.52-23.42.1
fixed
suse enterprise server 15
9.52-155.1
fixed
suse enterprise server 15 SP1
9.52-155.1
fixed
suse enterprise server 15 SP2
9.52-155.1
fixed
suse enterprise server 15 SP3
9.52-155.1
fixed
suse enterprise server 15 SP4
9.52-155.1
fixed
suse enterprise server 15 SP5
9.52-155.1
fixed
suse enterprise server 15 SP6
9.52-155.1
fixed
suse enterprise server 15 SP7
9.52-155.1
fixed
ghostscript-devel
suse enterprise desktop 15 SP2
9.52-155.1
fixed
suse enterprise desktop 15 SP3
9.52-155.1
fixed
suse enterprise desktop 15 SP4
9.52-155.1
fixed
suse enterprise desktop 15 SP5
9.52-155.1
fixed
suse enterprise desktop 15 SP6
9.52-155.1
fixed
suse enterprise desktop 15 SP7
9.52-155.1
fixed
suse enterprise sap 12 SP3
9.52-23.42.1
fixed
suse enterprise sap 12 SP4
9.52-23.42.1
fixed
suse enterprise sap 12 SP5
9.52-23.42.1
fixed
suse enterprise sap 15
9.52-155.1
fixed
suse enterprise sap 15 SP1
9.52-155.1
fixed
suse enterprise sap 15 SP2
9.52-155.1
fixed
suse enterprise sap 15 SP3
9.52-155.1
fixed
suse enterprise sap 15 SP4
9.52-155.1
fixed
suse enterprise sap 15 SP5
9.52-155.1
fixed
suse enterprise sap 15 SP6
9.52-155.1
fixed
suse enterprise sap 15 SP7
9.52-155.1
fixed
suse enterprise server 12 SP2
9.52-23.42.1
fixed
suse enterprise server 12 SP3
9.52-23.42.1
fixed
suse enterprise server 12 SP4
9.52-23.42.1
fixed
suse enterprise server 12 SP5
9.52-23.42.1
fixed
suse enterprise server 15
9.52-155.1
fixed
suse enterprise server 15 SP1
9.52-155.1
fixed
suse enterprise server 15 SP2
9.52-155.1
fixed
suse enterprise server 15 SP3
9.52-155.1
fixed
suse enterprise server 15 SP4
9.52-155.1
fixed
suse enterprise server 15 SP5
9.52-155.1
fixed
suse enterprise server 15 SP6
9.52-155.1
fixed
suse enterprise server 15 SP7
9.52-155.1
fixed
ghostscript-x11
suse enterprise desktop 15 SP2
9.52-155.1
fixed
suse enterprise desktop 15 SP3
9.52-155.1
fixed
suse enterprise desktop 15 SP4
9.52-155.1
fixed
suse enterprise desktop 15 SP5
9.52-155.1
fixed
suse enterprise desktop 15 SP6
9.52-155.1
fixed
suse enterprise desktop 15 SP7
9.52-155.1
fixed
suse enterprise sap 12 SP3
9.52-23.42.1
fixed
suse enterprise sap 12 SP4
9.52-23.42.1
fixed
suse enterprise sap 12 SP5
9.52-23.42.1
fixed
suse enterprise sap 15
9.52-155.1
fixed
suse enterprise sap 15 SP1
9.52-155.1
fixed
suse enterprise sap 15 SP2
9.52-155.1
fixed
suse enterprise sap 15 SP3
9.52-155.1
fixed
suse enterprise sap 15 SP4
9.52-155.1
fixed
suse enterprise sap 15 SP5
9.52-155.1
fixed
suse enterprise sap 15 SP6
9.52-155.1
fixed
suse enterprise sap 15 SP7
9.52-155.1
fixed
suse enterprise server 12 SP2
9.52-23.42.1
fixed
suse enterprise server 12 SP3
9.52-23.42.1
fixed
suse enterprise server 12 SP4
9.52-23.42.1
fixed
suse enterprise server 12 SP5
9.52-23.42.1
fixed
suse enterprise server 15
9.52-155.1
fixed
suse enterprise server 15 SP1
9.52-155.1
fixed
suse enterprise server 15 SP2
9.52-155.1
fixed
suse enterprise server 15 SP3
9.52-155.1
fixed
suse enterprise server 15 SP4
9.52-155.1
fixed
suse enterprise server 15 SP5
9.52-155.1
fixed
suse enterprise server 15 SP6
9.52-155.1
fixed
suse enterprise server 15 SP7
9.52-155.1
fixed
libspectre-devel
suse enterprise desktop 15 SP2
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP3
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP4
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP5
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP6
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP7
0.2.8-3.12.1
fixed
suse enterprise sap 12 SP3
0.2.7-12.12.1
fixed
suse enterprise sap 12 SP4
0.2.7-12.12.1
fixed
suse enterprise sap 12 SP5
0.2.7-12.12.1
fixed
suse enterprise sap 15
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP1
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP2
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP3
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP4
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP5
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP6
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP7
0.2.8-3.12.1
fixed
suse enterprise server 12 SP2
0.2.7-12.12.1
fixed
suse enterprise server 12 SP3
0.2.7-12.12.1
fixed
suse enterprise server 12 SP4
0.2.7-12.12.1
fixed
suse enterprise server 12 SP5
0.2.7-12.12.1
fixed
suse enterprise server 15
0.2.8-3.12.1
fixed
suse enterprise server 15 SP1
0.2.8-3.12.1
fixed
suse enterprise server 15 SP2
0.2.8-3.12.1
fixed
suse enterprise server 15 SP3
0.2.8-3.12.1
fixed
suse enterprise server 15 SP4
0.2.8-3.12.1
fixed
suse enterprise server 15 SP5
0.2.8-3.12.1
fixed
suse enterprise server 15 SP6
0.2.8-3.12.1
fixed
suse enterprise server 15 SP7
0.2.8-3.12.1
fixed
libspectre1
suse enterprise desktop 15 SP2
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP3
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP4
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP5
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP6
0.2.8-3.12.1
fixed
suse enterprise desktop 15 SP7
0.2.8-3.12.1
fixed
suse enterprise sap 12 SP3
0.2.7-12.12.1
fixed
suse enterprise sap 12 SP4
0.2.7-12.12.1
fixed
suse enterprise sap 12 SP5
0.2.7-12.12.1
fixed
suse enterprise sap 15
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP1
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP2
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP3
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP4
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP5
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP6
0.2.8-3.12.1
fixed
suse enterprise sap 15 SP7
0.2.8-3.12.1
fixed
suse enterprise server 12 SP2
0.2.7-12.12.1
fixed
suse enterprise server 12 SP3
0.2.7-12.12.1
fixed
suse enterprise server 12 SP4
0.2.7-12.12.1
fixed
suse enterprise server 12 SP5
0.2.7-12.12.1
fixed
suse enterprise server 15
0.2.8-3.12.1
fixed
suse enterprise server 15 SP1
0.2.8-3.12.1
fixed
suse enterprise server 15 SP2
0.2.8-3.12.1
fixed
suse enterprise server 15 SP3
0.2.8-3.12.1
fixed
suse enterprise server 15 SP4
0.2.8-3.12.1
fixed
suse enterprise server 15 SP5
0.2.8-3.12.1
fixed
suse enterprise server 15 SP6
0.2.8-3.12.1
fixed
suse enterprise server 15 SP7
0.2.8-3.12.1
fixed