CVE-2024-33869
published 2024-07-03CVE-2024-33869: An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of…
PriorityP425medium5.3CVSS 3.1
AVLACLPRNUIRSUCLILAL
EPSS
0.45%
36.6th percentile
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.03.1 | 10.03.1 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u7 | 9.53.3~dfsg-7+deb11u7 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u4 | 10.0.0~dfsg-11+deb12u4 |
| artifex | ghostscript | >= 0 < 10.03.1~dfsg~git20240518-1 | 10.03.1~dfsg~git20240518-1 |
| artifex | ghostscript | >= 0 < 10.03.1~dfsg~git20240518-1 | 10.03.1~dfsg~git20240518-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.12 | 9.50~dfsg-5ubuntu4.12 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.7 | 9.55.0~dfsg1-0ubuntu5.7 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.1 | 10.02.1~dfsg1-0ubuntu7.1 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-06-17·CVSS 5.5
CVE-2024-33871 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript did not properly restrict eexec
seeds to those specified by the Type 1 Font Format standard when
SAFER mode is used. An attacker could use this issue to bypass SAFER
restrictions and cause unspecified impact. (CVE-2023-52722)
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.10.
Thomas Rinsma discovered that Ghostscript did not prevent changes to
uniprint device argument strings after SAFER is activated, resulting
in a format-string vulnerability. An attacker could possibly use this
to execute arbitrary code. (CVE-2024-29510)
Zdenek Hutyra discovered that Ghostscript did not properly perform
path reduction when validating paths. An a
Red Hat
ghostscript: path traversal and command execution due to path reduction
vendor_redhat·2024-05-16·CVSS 5.3
CVE-2024-33869 [MEDIUM] CWE-23 ghostscript: path traversal and command execution due to path reduction
ghostscript: path traversal and command execution due to path reduction
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.
A flaw was found in Ghostscript. In certain circumstances, path reduction in the "gp_validate_path_len" function may allow path traversal or possible command execution.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: ghost
Debian
CVE-2024-33869: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal an...
vendor_debian·2024·CVSS 5.3
CVE-2024-33869 [MEDIUM] CVE-2024-33869: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal an...
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u4)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u7)
forky: resolved (fixed in 10.03.1~dfsg~git20240518-1)
sid: resolved (fixed in 10.03.1~dfsg~git20240518-1)
trixie: resolved (fixed in 10.03.1~dfsg~git20240518-1)
OSV
CVE-2024-33869: An issue was discovered in Artifex Ghostscript before 10
osv·2024-07-03·CVSS 5.3
CVE-2024-33869 [MEDIUM] CVE-2024-33869: An issue was discovered in Artifex Ghostscript before 10
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.
GHSA
GHSA-v6hc-9c6c-f599: An issue was discovered in Artifex Ghostscript before 10
ghsa_unreviewed·2024-07-03
CVE-2024-33869 [MEDIUM] CWE-22 GHSA-v6hc-9c6c-f599: An issue was discovered in Artifex Ghostscript before 10
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.
OSV
ghostscript vulnerabilities
osv·2024-06-17·CVSS 5.5
CVE-2023-52722 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript did not properly restrict eexec
seeds to those specified by the Type 1 Font Format standard when
SAFER mode is used. An attacker could use this issue to bypass SAFER
restrictions and cause unspecified impact. (CVE-2023-52722)
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.10.
Thomas Rinsma discovered that Ghostscript did not prevent changes to
uniprint device argument strings after SAFER is activated, resulting
in a format-string vulnerability. An attacker could possibly use this
to execute arbitrary code. (CVE-2024-29510)
Zdenek Hutyra discovered that Ghostscript did not properly perform
path reduction when validating paths. An attacker could use this to
access file locations outside of those all
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-03
Published