CVE-2024-29509
published 2024-07-03CVE-2024-29509: Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.45%
70.3th percentile
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.03.0 | 10.03.0 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u5 | 10.0.0~dfsg-11+deb12u5 |
| artifex | ghostscript | >= 0 < 10.03.0~dfsg-1 | 10.03.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.03.0~dfsg-1 | 10.03.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.13 | 9.50~dfsg-5ubuntu4.13 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.9 | 9.55.0~dfsg1-0ubuntu5.9 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.3 | 10.02.1~dfsg1-0ubuntu7.3 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u5 (bookworm) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ghostscript vulnerabilities
osv·2024-07-15·CVSS 8.8
CVE-2024-29506 [HIGH] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled certain long PDF
filter names. An attacker could possibly use this issue to cause
Ghostscript to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29506)
It was discovered that Ghostscript incorrectly handled certain API
parameters. An attacker could possibly use this issue to cause Ghostscript
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2024-29507)
It was discovered that Ghostscript incorrectly handled certain BaseFont
names. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-29508)
It was discovered
OSV
CVE-2024-29509: Artifex Ghostscript before 10
osv·2024-07-03·CVSS 8.8
CVE-2024-29509 [HIGH] CVE-2024-29509: Artifex Ghostscript before 10
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
GHSA
GHSA-8w32-6chg-qv5f: Artifex Ghostscript before 10
ghsa_unreviewed·2024-07-03
CVE-2024-29509 [HIGH] CWE-787 GHSA-8w32-6chg-qv5f: Artifex Ghostscript before 10
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-07-15·CVSS 8.8
CVE-2024-29508 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled certain long PDF
filter names. An attacker could possibly use this issue to cause
Ghostscript to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29506)
It was discovered that Ghostscript incorrectly handled certain API
parameters. An attacker could possibly use this issue to cause Ghostscript
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2024-29507)
It was discovered that Ghostscript incorrectly handled certain BaseFont
names. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or p
Red Hat
ghostscript: heap buffer overflow via the PDFPassword parameter
vendor_redhat·2024-07-03·CVSS 8.8
CVE-2024-29509 [HIGH] CWE-122 ghostscript: heap buffer overflow via the PDFPassword parameter
ghostscript: heap buffer overflow via the PDFPassword parameter
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
A flaw was found in Ghostscript. The `runpdf` command allowed the new C-based PDF interpreter to be invoked from within PS. With this, it can pass various flags and arguments (for example, see `pdf_impl_set_param`) normally passed via the command line when the PDF interpreter is invoked directly. Because PS-strings are not null-terminated, this issue will result in a heap buffer overflow when a value of `PDFPassword` is supplied with a NULL byte in the middle.
Statement: This vulnerability in Ghostscript, while serious, is considered moderate rather than important due to several mitigating factors.
Debian
CVE-2024-29509: ghostscript - Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e...
vendor_debian·2024·CVSS 8.8
CVE-2024-29509 [HIGH] CVE-2024-29509: ghostscript - Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e...
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u5)
bullseye: resolved
forky: resolved (fixed in 10.03.0~dfsg-1)
sid: resolved (fixed in 10.03.0~dfsg-1)
trixie: resolved (fixed in 10.03.0~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.ghostscript.com/show_bug.cgi?id=707510https://git.ghostscript.com/?p=ghostpdl.git%3Bh=917b3a71fb20748965254631199ad98210d6c2fbhttps://www.openwall.com/lists/oss-security/2024/07/03/7https://bugs.ghostscript.com/show_bug.cgi?id=707510https://git.ghostscript.com/?p=ghostpdl.git%3Bh=917b3a71fb20748965254631199ad98210d6c2fbhttps://www.openwall.com/lists/oss-security/2024/07/03/7
2024-07-03
Published