Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-46956

Опубликовано: 10 нояб. 2024
Источник: debian
EPSS Низкий

Описание

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ghostscriptfixed10.04.0~dfsg-1package

Примечания

  • https://bugs.ghostscript.com/show_bug.cgi?id=707895

  • https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca

  • https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=ea69a1388245ad959d31c272b5ba66d40cebba2c (ghostpdl-10.04.0)

EPSS

Процентиль: 40%
0.0018
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVSS3: 7.8
redhat
7 месяцев назад

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVSS3: 7.8
nvd
7 месяцев назад

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVSS3: 7.8
github
7 месяцев назад

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVSS3: 7.8
fstec
9 месяцев назад

Уязвимость компонента psi/zfile.c набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 40%
0.0018
Низкий