CVE-2024-29511
published 2024-07-03CVE-2024-29511: Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.14%
62.9th percentile
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.03.1 | 10.03.1 |
| artifex | ghostscript | >= 0 < 10.03.0~dfsg-1 | 10.03.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.03.0~dfsg-1 | 10.03.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.13 | 9.50~dfsg-5ubuntu4.13 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.9 | 9.55.0~dfsg1-0ubuntu5.9 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.3 | 10.02.1~dfsg1-0ubuntu7.3 |
| debian | ghostscript | < ghostscript 10.03.0~dfsg-1 (forky) | ghostscript 10.03.0~dfsg-1 (forky) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ghostscript vulnerabilities
osv·2024-07-15·CVSS 8.8
CVE-2024-29506 [HIGH] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled certain long PDF
filter names. An attacker could possibly use this issue to cause
Ghostscript to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29506)
It was discovered that Ghostscript incorrectly handled certain API
parameters. An attacker could possibly use this issue to cause Ghostscript
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2024-29507)
It was discovered that Ghostscript incorrectly handled certain BaseFont
names. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-29508)
It was discovered
GHSA
GHSA-g9m4-vfq7-w439: Artifex Ghostscript before 10
ghsa_unreviewed·2024-07-03
CVE-2024-29511 [HIGH] CWE-489 GHSA-g9m4-vfq7-w439: Artifex Ghostscript before 10
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
OSV
CVE-2024-29511: Artifex Ghostscript before 10
osv·2024-07-03·CVSS 7.5
CVE-2024-29511 [HIGH] CVE-2024-29511: Artifex Ghostscript before 10
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-07-15·CVSS 8.8
CVE-2024-29508 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled certain long PDF
filter names. An attacker could possibly use this issue to cause
Ghostscript to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29506)
It was discovered that Ghostscript incorrectly handled certain API
parameters. An attacker could possibly use this issue to cause Ghostscript
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2024-29507)
It was discovered that Ghostscript incorrectly handled certain BaseFont
names. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or p
Red Hat
ghostscript: ghostscript: arbitrary file read/write through Tesseract configuration
vendor_redhat·2024-07-03·CVSS 7.5
CVE-2024-29511 [HIGH] CWE-22 ghostscript: ghostscript: arbitrary file read/write through Tesseract configuration
ghostscript: ghostscript: arbitrary file read/write through Tesseract configuration
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
A vulnerability was found in Ghostscript. When Tesseract is used for Optical Character Recognition (OCR), a directory traversal issue allows arbitrary file reading and writing of error messages to arbitrary files via the OCRLanguage. This issue causes an arbitrary file read/write through the Tesseract configuration.
Statement: The CVE-2024-29511 vulnerability in Ghostscript, when used with Tesseract for OCR, is class
Debian
CVE-2024-29511: ghostscript - Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a direct...
vendor_debian·2024·CVSS 7.5
CVE-2024-29511 [HIGH] CVE-2024-29511: ghostscript - Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a direct...
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.03.0~dfsg-1)
sid: resolved (fixed in 10.03.0~dfsg-1)
trixie: resolved (fixed in 10.03.0~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.ghostscript.com/show_bug.cgi?id=707510https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=3d4cfdc1a44https://www.openwall.com/lists/oss-security/2024/07/03/7https://bugs.ghostscript.com/show_bug.cgi?id=707510https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=3d4cfdc1a44https://www.openwall.com/lists/oss-security/2024/07/03/7
2024-07-03
Published