Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-29508

Опубликовано: 03 июл. 2024
Источник: redhat
CVSS3: 4.4

Описание

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

A flaw was found in Ghostscript. Thepdf_base_font_alloc function used by the pdfwrite device will use a hexadecimal pointer representation for the constructed BaseFont name if the input name is empty. This flaw allows an attacker to obtain this pointer value by reading back to the output file after writing to a temporary writable and readable location.

Отчет

The vulnerability in Ghostscript’s pdf_base_font_alloc function represents a moderate severity issue rather than a important one due to the nature of the exposed information. While the hexadecimal pointer representation of the BaseFont name can be read from the output file, it does not directly reveal sensitive data such as user credentials or confidential content. Instead, the pointer value may offer insights into the memory layout or internal data structures, which, although potentially useful for further exploitation, requires additional steps and context to leverage effectively.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10ghostscriptNot affected
Red Hat Enterprise Linux 6ghostscriptOut of support scope
Red Hat Enterprise Linux 7ghostscriptOut of support scope
Red Hat Enterprise Linux 8ghostscriptNot affected
Red Hat Enterprise Linux 8gimp:flatpak/ghostscriptNot affected
Red Hat Enterprise Linux 9ghostscriptWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2295627ghostscript: heap pointer leak in pdf_base_font_alloc()

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
12 месяцев назад

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

CVSS3: 3.3
nvd
12 месяцев назад

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

CVSS3: 3.3
debian
12 месяцев назад

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure ...

suse-cvrf
11 месяцев назад

Security update for ghostscript

suse-cvrf
12 месяцев назад

Security update for ghostscript

4.4 Medium

CVSS3