Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-46956

Опубликовано: 10 нояб. 2024
Источник: redhat
CVSS3: 7.8

Описание

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

A flaw was found in Artifex Ghostscript's psi/zfile.c component. This vulnerability allows arbitrary code execution via out-of-bounds data access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ghostscriptOut of support scope
Red Hat Enterprise Linux 8gimp:flatpak/ghostscriptWill not fix
Red Hat Enterprise Linux 10ghostscriptFixedRHSA-2025:749913.05.2025
Red Hat Enterprise Linux 8ghostscriptFixedRHSA-2025:436230.04.2025
Red Hat Enterprise Linux 9ghostscriptFixedRHSA-2025:742213.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2325047ghostscript: Out-of-Bounds Data Access in Ghostscript Leads to Arbitrary Code Execution

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVSS3: 7.8
nvd
7 месяцев назад

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVSS3: 7.8
debian
7 месяцев назад

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 1 ...

CVSS3: 7.8
github
7 месяцев назад

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVSS3: 7.8
fstec
9 месяцев назад

Уязвимость компонента psi/zfile.c набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3