CVE-2024-46953
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.04.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0 sp5 | |
| Version 12 sp5 | |
| Version 12 sp5 |
References (5)
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.