Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-46951

Опубликовано: 10 нояб. 2024
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

A flaw was found in Artifex Ghostscript's psi/zcolor.c component. This vulnerability allows arbitrary code execution via an unchecked implementation pointer in the Pattern color space.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ghostscriptOut of support scope
Red Hat Enterprise Linux 8gimp:flatpak/ghostscriptWill not fix
Red Hat Enterprise Linux 10ghostscriptFixedRHSA-2025:749913.05.2025
Red Hat Enterprise Linux 8ghostscriptFixedRHSA-2025:436230.04.2025
Red Hat Enterprise Linux 9ghostscriptFixedRHSA-2025:742213.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2325043ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space

EPSS

Процентиль: 19%
0.00061
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

CVSS3: 7.8
nvd
7 месяцев назад

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

CVSS3: 7.8
debian
7 месяцев назад

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before ...

CVSS3: 7.8
github
7 месяцев назад

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

CVSS3: 7.8
fstec
9 месяцев назад

Уязвимость компонента psi/zcolor.c интерпретатора набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 19%
0.00061
Низкий

7.8 High

CVSS3