CVE-2020-15900
Ghostscript vulnerability analysis and mitigation

Overview

CVE-2020-15900 is a memory corruption vulnerability discovered in Artifex Ghostscript versions 9.50 and 9.52. The vulnerability was disclosed on July 28, 2020, and affects the PostScript interpreter's handling of the 'rsearch' operator. The issue involves incorrect calculation of the 'post' size, which could result in a size that was too large and potentially underflow to max uint32_t (Artifex Advisory).

Technical details

The vulnerability stems from a memory corruption issue in the PostScript interpreter's implementation of the non-standard 'rsearch' operator. The calculation for the 'post' size was incorrect, resulting in a potential size underflow to max uint32_t. This could allow overriding of file access controls. The issue was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b, which corrected the 'rsearch' calculation and fixed the return of the correct 'pre' string with empty string match (Artifex Advisory, GitHub Commit).

Impact

The vulnerability could allow attackers to override file access controls and potentially execute arbitrary code or access arbitrary files. The issue affects the SAFER sandbox implementation in Ghostscript, potentially allowing sandbox escape (Artifex Advisory, Ubuntu Notice).

Exploitability

The vulnerability can be triggered by processing specially crafted PostScript files. An attacker could exploit this issue if a user or automated system were tricked into processing a malicious file (Ubuntu Notice).

Mitigation and workarounds

The vulnerability was fixed in later versions of Ghostscript. Users are advised to upgrade to a patched version. Various Linux distributions have released security updates to address this vulnerability, including Ubuntu, OpenSUSE, and Gentoo (Ubuntu Notice, OpenSUSE Notice, Gentoo Advisory).

Additional resources


SourceThis report was generated using AI

Related Ghostscript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59800MEDIUM5.5
  • Ghostscript logoGhostscript
  • libgs
NoYesSep 22, 2025
CVE-2025-59799MEDIUM5.5
  • Ghostscript logoGhostscript
  • ghostscript
NoYesSep 22, 2025
CVE-2025-59798MEDIUM5.5
  • Ghostscript logoGhostscript
  • ghostscript-gtk-debuginfo
NoYesSep 22, 2025
CVE-2025-59801MEDIUM4.3
  • Ghostscript logoGhostscript
  • ghostscript
NoYesSep 22, 2025
CVE-2026-6192LOW1.9
  • Ghostscript logoGhostscript
  • qtwebengine-opensource-src
NoYesApr 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management