
Cloud Vulnerability DB
A community-led vulnerabilities database
A trivial sandbox escape vulnerability (CVE-2021-3781) was discovered in the Ghostscript interpreter, affecting versions from 9.50 onwards. The vulnerability, identified in September 2021, allows attackers to bypass the -dSAFER option protection by injecting a specially crafted pipe command. This flaw specifically affects Unix-like systems and does not impact Windows environments (Ghostscript Advisory, Debian Tracker).
The vulnerability stems from insufficient file access protection in Ghostscript's handling of the '%pipe%' PostScript device, particularly when combined with Ghostscript's need to create and control temporary files in conventional directories like '/tmp' or '/temp'. The issue occurs because the permission checking only validated the sub-string following the device specifier, rather than the entire file name string including the device specifier. The vulnerability has been assigned a CVSS v3.1 base score of 9.9 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (NVD, Ghostscript Advisory).
The vulnerability allows attackers to execute arbitrary commands on the system in the context of the Ghostscript interpreter. The highest threats from this vulnerability affect system confidentiality, integrity, and availability. The most severe impacts are particularly concerning when the exploit is executed with high privileges (root/superuser level) (NVD, Debian Tracker).
The vulnerability is exploitable through specially crafted PostScript files that can bypass the sandbox protection mechanism. The exploit is specifically effective on Unix-like systems and requires the processing of a maliciously crafted file, either by a user or an automated system (Ghostscript Advisory).
The vulnerability was fixed in Ghostscript version 9.55.0 and later releases. The solution involves including the device specifier string ('%pipe%') in the permissions checking, ensuring that the entire file name string is validated. Users are advised to upgrade to version 9.55.0 or later to remediate this vulnerability (Ghostscript Advisory, Debian Tracker).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."