Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-46954

Опубликовано: 10 нояб. 2024
Источник: redhat
CVSS3: 7.8

Описание

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

A flaw was found in Ghostscript/base/gp_utf8.c. This vulnerability allows directory traversal via overlong UTF-8 encoding, potentially leading to unauthorized access to filesystem directories.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ghostscriptOut of support scope
Red Hat Enterprise Linux 8gimp:flatpak/ghostscriptWill not fix
Red Hat Enterprise Linux 10ghostscriptFixedRHSA-2025:749913.05.2025
Red Hat Enterprise Linux 8ghostscriptFixedRHSA-2025:436230.04.2025
Red Hat Enterprise Linux 9ghostscriptFixedRHSA-2025:742213.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2325044ghostscript: Directory Traversal in Ghostscript via Overlong UTF-8 Encoding

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

CVSS3: 7.8
nvd
7 месяцев назад

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

CVSS3: 7.8
debian
7 месяцев назад

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Gh ...

CVSS3: 8.4
github
7 месяцев назад

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

oracle-oval
29 дней назад

ELSA-2025-7422: ghostscript security update (MODERATE)

7.8 High

CVSS3