Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-28879

34
FAUCET Score

CVE-2023-28879 is a critical buffer overflow vulnerability in Artifex Ghostscript through version 10.01.0, specifically impacting the BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode functions within base/sbcp.c. This flaw allows for potential data corruption within the PostScript interpreter. With a CVSS score of 9.8 (CRITICAL), it is easily exploitable over the network with low complexity, enabling full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 10.01.0CPE matchmatch criteria
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
6.34%
Probability of exploitation in next 30 days
EPSS Percentile
92.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0634 is in the 88th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: ghostscript-0:9.27-11.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ghostscript-0:9.54.0-13.el9
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gimp:flatpak/ghostscript

Vendor Advisories (1)

redhatCVE-2023-28879Moderate

ghostscript: buffer overflow in base/sbcp.c leading to data corruption

Mar 31, 2023

References

bugs.ghostscript.com / show_bug.cgi
ExploitVendor Advisory
ghostscript.readthedocs.io / en/latest/News.html
Release Notes
git.ghostscript.com
lists.debian.org / debian-lts-announce/2023/04/msg00003.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DHJX62KSRIOBZA6FKONMJP7MEFY7LTH2
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MADLP3GWJFLLFVNZGEDNPMDQR6CCXAHN
security.gentoo.org / glsa/202309-03
debian.org / security/2023/dsa-5383
Third Party Advisory
openwall.com / lists/oss-security/2023/04/12/4