Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-46953

Опубликовано: 10 нояб. 2024
Источник: redhat
CVSS3: 7.8

Описание

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

A flaw was found in Artifex Ghostscript base/gsdevice.c. This vulnerability allows path truncation, path traversal, and possible code execution via an integer overflow when parsing the filename format string for the output filename.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ghostscriptOut of support scope
Red Hat Enterprise Linux 8gimp:flatpak/ghostscriptWill not fix
Red Hat Enterprise Linux 10ghostscriptFixedRHSA-2025:749913.05.2025
Red Hat Enterprise Linux 8ghostscriptFixedRHSA-2025:436230.04.2025
Red Hat Enterprise Linux 9ghostscriptFixedRHSA-2025:742213.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2325045ghostscript: Path Traversal and Code Execution via Integer Overflow in Ghostscript

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
12 месяцев назад

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

CVSS3: 7.8
nvd
12 месяцев назад

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

CVSS3: 7.8
debian
12 месяцев назад

An issue was discovered in base/gsdevice.c in Artifex Ghostscript befo ...

CVSS3: 7.8
github
12 месяцев назад

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

CVSS3: 7.8
fstec
около 1 года назад

Уязвимость компонента base/gsdevice.c набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3