CVE-2021-3781

CRITICAL

Ghostscript - Command Execution via SAFER Sandbox Escape

Title source: manual
STIX 2.1

Description

A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

References (3)

Core 3
Core References
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202211-11
Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2002271

Scores

CVSS v3 9.9
EPSS 0.0649
EPSS Percentile 91.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-20
Status published
Products (5)
artifex/ghostscript 9.50
artifex/ghostscript 9.52
artifex/ghostscript 9.53.3
artifex/ghostscript 9.54.0
fedoraproject/fedora 34
Published Feb 16, 2022
Tracked Since Feb 18, 2026