CVE Identifier: CVE-2023-4042 Public Date: August 23, 2023 Last Modified: October 6, 2025 Severity: Low (CVSS v3 Score: 5.5) Description: A flaw found in ghostscript, where the fix for CVE-2020-16305 was not included in the RHSA-2021:1852-06 advisory. Affected Products: - Red Hat Enterprise Linux 8 (ghostscript - Fixed in RHSA-2023:7053) - Red Hat Enterprise Linux 6 (Not affected) - Red Hat Enterprise Linux 7 (Not affected) - Red Hat Enterprise Linux 8 (gimp:flatpak/ghostscript - Affected) - Red Hat Enterprise Linux 9 (Not affected) Common Vulnerability Scoring System (CVSS) Score Details: - CVSS v3 Base Score: 5.5 - Attack Vector: Local - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High Weakness (CWE): CWE-125 - Out-of-bounds Read External References: - CVE Record - NVD Detail - Bugzilla Report