CVE-2021-3781 describes a critical sandbox escape flaw in the Ghostscript interpreter, affecting Artifex Ghostscript and Fedora Project Ghostscript. This vulnerability allows an attacker to execute arbitrary commands on the system by injecting a specially crafted pipe command, even when the -dSAFER option is enabled. With a CVSS score of 9.9 (CRITICAL), it poses a significant threat to confidentiality, integrity, and availability, requiring low privileges and no user interaction for exploitation over the network. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.50CPE matchmatch criteria | cpe:2.3:a:artifex:ghostscript:9.50:*:*:*:*:*:*:* | ||
9.52CPE matchmatch criteria | cpe:2.3:a:artifex:ghostscript:9.52:*:*:*:*:*:*:* | ||
9.53.3CPE matchmatch criteria | cpe:2.3:a:artifex:ghostscript:9.53.3:*:*:*:*:*:*:* | ||
9.54.0CPE matchmatch criteria | cpe:2.3:a:artifex:ghostscript:9.54.0:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.