CVE-2024-29508
published 2024-07-03CVE-2024-29508: Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.38%
29.8th percentile
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.03.0 | 10.03.0 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u8 | 9.53.3~dfsg-7+deb11u8 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u5 | 10.0.0~dfsg-11+deb12u5 |
| artifex | ghostscript | >= 0 < 10.03.0~dfsg-1 | 10.03.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.03.0~dfsg-1 | 10.03.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.13 | 9.50~dfsg-5ubuntu4.13 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.12 | 9.55.0~dfsg1-0ubuntu5.12 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.9 | 9.55.0~dfsg1-0ubuntu5.9 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.7 | 10.02.1~dfsg1-0ubuntu7.7 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.3 | 10.02.1~dfsg1-0ubuntu7.3 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.16.04.14+esm9 | 9.26~dfsg+0-0ubuntu0.16.04.14+esm9 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.18.04.18+esm4 | 9.26~dfsg+0-0ubuntu0.18.04.18+esm4 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.15+esm1 | 9.50~dfsg-5ubuntu4.15+esm1 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm) |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ghostscript vulnerabilities
osv·2025-07-08·CVSS 4.3
CVE-2023-39327 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that OpenJPEG, vendored in Ghostscript did not correctly
handle large image files. If a user or system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2023-39327) Thomas Rinsma discovered that Ghostscript did
not correctly handle printing certain variables. An attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-29508) It was discovered
that Ghostscript did not correctly handle loading certain libraries. An
attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 16.04 LT
OSV
ghostscript vulnerabilities
osv·2024-07-15·CVSS 8.8
CVE-2024-29506 [HIGH] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled certain long PDF
filter names. An attacker could possibly use this issue to cause
Ghostscript to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29506)
It was discovered that Ghostscript incorrectly handled certain API
parameters. An attacker could possibly use this issue to cause Ghostscript
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2024-29507)
It was discovered that Ghostscript incorrectly handled certain BaseFont
names. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-29508)
It was discovered
OSV
CVE-2024-29508: Artifex Ghostscript before 10
osv·2024-07-03·CVSS 3.3
CVE-2024-29508 [LOW] CVE-2024-29508: Artifex Ghostscript before 10
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
GHSA
GHSA-w2wv-53w9-5r3r: Artifex Ghostscript before 10
ghsa_unreviewed·2024-07-03
CVE-2024-29508 [LOW] CWE-122 GHSA-w2wv-53w9-5r3r: Artifex Ghostscript before 10
Artifex Ghostscript before 10.0.3.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2025-07-08·CVSS 4.3
CVE-2025-27835 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that OpenJPEG, vendored in Ghostscript did not correctly
handle large image files. If a user or system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2023-39327) Thomas Rinsma discovered that Ghostscript did
not correctly handle printing certain variables. An attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-29508) It was discovered
that Ghostscript did not correctly handle loading certain libraries. An
attacker could possibly use this issue
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-07-15·CVSS 8.8
CVE-2024-29508 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled certain long PDF
filter names. An attacker could possibly use this issue to cause
Ghostscript to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29506)
It was discovered that Ghostscript incorrectly handled certain API
parameters. An attacker could possibly use this issue to cause Ghostscript
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2024-29507)
It was discovered that Ghostscript incorrectly handled certain BaseFont
names. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or p
Red Hat
ghostscript: heap pointer leak in pdf_base_font_alloc()
vendor_redhat·2024-07-03·CVSS 3.3
CVE-2024-29508 [LOW] CWE-401 ghostscript: heap pointer leak in pdf_base_font_alloc()
ghostscript: heap pointer leak in pdf_base_font_alloc()
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
A flaw was found in Ghostscript. The`pdf_base_font_alloc` function used by the `pdfwrite` device will use a hexadecimal pointer representation for the constructed BaseFont name if the input name is empty. This flaw allows an attacker to obtain this pointer value by reading back to the output file after writing to a temporary writable and readable location.
Statement: The vulnerability in Ghostscript’s pdf_base_font_alloc function represents a moderate severity issue rather than a important one due to the nature of the exposed information. While the hexadecimal pointer representation
Debian
CVE-2024-29508: ghostscript - Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observab...
vendor_debian·2024·CVSS 3.3
CVE-2024-29508 [LOW] CVE-2024-29508: ghostscript - Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observab...
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u5)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u8)
forky: resolved (fixed in 10.03.0~dfsg-1)
sid: resolved (fixed in 10.03.0~dfsg-1)
trixie: resolved (fixed in 10.03.0~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.ghostscript.com/show_bug.cgi?id=707510https://git.ghostscript.com/?p=ghostpdl.git%3Bh=ff1013a0ab485b66783b70145e342a82c670906ahttps://www.openwall.com/lists/oss-security/2024/07/03/7https://bugs.ghostscript.com/show_bug.cgi?id=707510https://git.ghostscript.com/?p=ghostpdl.git%3Bh=ff1013a0ab485b66783b70145e342a82c670906ahttps://lists.debian.org/debian-lts-announce/2024/10/msg00022.htmlhttps://www.openwall.com/lists/oss-security/2024/07/03/7
2024-07-03
Published