CVE-2024-29507
published 2024-07-03CVE-2024-29507: Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
PriorityP429medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
EPSS
0.72%
50.0th percentile
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.03.0 | 10.03.0 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u5 | 10.0.0~dfsg-11+deb12u5 |
| artifex | ghostscript | >= 0 < 10.03.0~dfsg-1 | 10.03.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.03.0~dfsg-1 | 10.03.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.13 | 9.50~dfsg-5ubuntu4.13 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.9 | 9.55.0~dfsg1-0ubuntu5.9 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.3 | 10.02.1~dfsg1-0ubuntu7.3 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm) |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-07-15·CVSS 8.8
CVE-2024-29508 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled certain long PDF
filter names. An attacker could possibly use this issue to cause
Ghostscript to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29506)
It was discovered that Ghostscript incorrectly handled certain API
parameters. An attacker could possibly use this issue to cause Ghostscript
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2024-29507)
It was discovered that Ghostscript incorrectly handled certain BaseFont
names. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or p
Red Hat
ghostscript: stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters
vendor_redhat·2024-07-03·CVSS 5.4
CVE-2024-29507 [MEDIUM] CWE-121 ghostscript: stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters
ghostscript: stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
A flaw was found in Ghostscript. Under specific conditions, the `cidfsubstpath` and `cidfsubstfont` parameters set by corresponding Postscript objects are used to load substitute fonts in `pdfi_open_CIDFont_substitute_file`. The values are copied via `memcpy` into the `fontfname` buffer without bounds checks. This flaw allows an attacker to pass values larger than the buffer size to trigger a stack buffer overflow, leading to a denial of service or other unexpected behavior.
Statement: The buffer overflow vulnerability in Ghostscript, while serious, is categorized as
Debian
CVE-2024-29507: ghostscript - Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow v...
vendor_debian·2024·CVSS 5.4
CVE-2024-29507 [MEDIUM] CVE-2024-29507: ghostscript - Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow v...
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u5)
bullseye: resolved
forky: resolved (fixed in 10.03.0~dfsg-1)
sid: resolved (fixed in 10.03.0~dfsg-1)
trixie: resolved (fixed in 10.03.0~dfsg-1)
OSV
ghostscript vulnerabilities
osv·2024-07-15·CVSS 8.8
CVE-2024-29506 [HIGH] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled certain long PDF
filter names. An attacker could possibly use this issue to cause
Ghostscript to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29506)
It was discovered that Ghostscript incorrectly handled certain API
parameters. An attacker could possibly use this issue to cause Ghostscript
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2024-29507)
It was discovered that Ghostscript incorrectly handled certain BaseFont
names. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-29508)
It was discovered
GHSA
GHSA-mjm5-gj95-f347: Artifex Ghostscript before 10
ghsa_unreviewed·2024-07-03
CVE-2024-29507 [MEDIUM] CWE-120 GHSA-mjm5-gj95-f347: Artifex Ghostscript before 10
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
OSV
CVE-2024-29507: Artifex Ghostscript before 10
osv·2024-07-03·CVSS 5.4
CVE-2024-29507 [MEDIUM] CVE-2024-29507: Artifex Ghostscript before 10
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.ghostscript.com/show_bug.cgi?id=707510https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=7745dbe24514https://www.openwall.com/lists/oss-security/2024/07/03/7https://bugs.ghostscript.com/show_bug.cgi?id=707510https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=7745dbe24514https://www.openwall.com/lists/oss-security/2024/07/03/7
2024-07-03
Published