CVE-2024-29508Heap-based Buffer Overflow in Ghostscript

Severity
3.3LOWNVD
EPSS
0.0%
top 89.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3
Latest updateJul 8

Description

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDartifex/ghostscript< 10.03.0
Debianartifex/ghostscript< 9.53.3~dfsg-7+deb11u8+3

🔴Vulnerability Details

5
OSV
ghostscript vulnerabilities2025-07-08
OSV
ghostscript vulnerabilities2024-07-15
OSV
CVE-2024-29508: Artifex Ghostscript before 102024-07-03
CVEList
CVE-2024-29508: Artifex Ghostscript before 102024-07-03
GHSA
GHSA-w2wv-53w9-5r3r: Artifex Ghostscript before 102024-07-03

📋Vendor Advisories

4
Ubuntu
Ghostscript vulnerabilities2025-07-08
Ubuntu
Ghostscript vulnerabilities2024-07-15
Red Hat
ghostscript: heap pointer leak in pdf_base_font_alloc()2024-07-03
Debian
CVE-2024-29508: ghostscript - Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observab...2024
CVE-2024-29508 — Heap-based Buffer Overflow | cvebase