Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-29511

Опубликовано: 03 июл. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.

РелизСтатусПримечание
devel

released

10.02.1~dfsg1-0ubuntu9
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

released

9.55.0~dfsg1-0ubuntu5.9
mantic

ignored

end of life, was needed
noble

released

10.02.1~dfsg1-0ubuntu7.3
upstream

released

10.03.0~dfsg-1

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 4.4
redhat
больше 1 года назад

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.

CVSS3: 7.5
nvd
больше 1 года назад

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.

CVSS3: 7.5
debian
больше 1 года назад

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, ha ...

CVSS3: 7.5
github
больше 1 года назад

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость функцию файла /tmp/out компонента Tesseract набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

7.5 High

CVSS3

Уязвимость CVE-2024-29511