Security Vulnerability Fixed in Ghostscript 10.01.2

Artifex·June 28, 2023

GhostscriptSecurityRelease
Security Vulnerability Fixed in Ghostscript 10.01.2

Artifex Software is pleased to report that a recently disclosed security vulnerability in Ghostscript has been resolved. This vulnerability affects all Ghostscript/GhostPDL versions prior to 10.1.2. A CVE (Common Vulnerabilities and Exposures) identifier has been assigned to the issue, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36664.

As of June 21, 2023, the reported problem has been fixed. The patch has been released in Ghostscript 10.01.2, available here. We recommend applying this security fix as soon as possible.

Artifex takes security issues very seriously and strongly encourages responsible and coordinated disclosure of vulnerabilities. Users of Ghostscript are urged to update their software to the latest version immediately. By doing so, they will be able to mitigate the risk associated with this vulnerability and ensure the security and integrity of their systems.