Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ghostscript Code Execution Vulnerability #14

Open
tenajsystems opened this issue Oct 31, 2023 · 3 comments
Open

Ghostscript Code Execution Vulnerability #14

tenajsystems opened this issue Oct 31, 2023 · 3 comments

Comments

@tenajsystems
Copy link

Our Qualys vulnerability scanner is detecting vulnerability with Ghost Trap per C:\Program Files\GhostTrap\bin\gsdll64.dll Version is 0.0.9.27. after we setup Print Deploy Mobility Print. It doesn't appear that this has been updated since 2019 (as shown here: https://www.papercut.com/help/manuals/mobility-print/how-it-works/ghost-trap-script/ and here: https://github.com/PaperCutSoftware/GhostTrap). Any thoughts on when it will be updated and how we can remediate the vulnerability which is at level 4 out of level 5? Thank you!

@Joffcom
Copy link

Joffcom commented Nov 1, 2023

I would email PaperCut support with the details, while the DLL itself is vulnerable there is a chance that Ghosttrap itself isn’t as it is designed to be a secure sandbox.

There is a KB page listing the CVEs that dont apply here: https://www.papercut.com/kb/Main/GhostScriptVulnerabilities

@asosin007
Copy link

The latest version of GhostTrap to Version 1.5.10.03 contains Ghostscript to version 10.03.1 which has vulnerabilities.
Does anyone know when a newer verions fo GhostTrap will be released that contains Ghostscript version 10.04.0 that doesn't have vulnerabilities ?

@squashedbeetle
Copy link

Hi @asosin007
Just had a chat with our development team - the work is in progress, so a new update will be released which includes an updated Ghostscript in the next month or two.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants