/ Ghostscript bug could allow rogue documents to run system commands
Unfortunately, until the latest release of Ghostscript, now at version 10.01.2, the product had a bug, dubbed CVE-2023-36664, that could allow rogue documents not only to create pages of text and graphics, but also to send system commands into the Ghostscript rendering engine and trick the software into running them:
— nakedsecurity.sophos.com/2023/07…commands