CVE-2024-33870

Severity
6.3MEDIUM
EPSS
0.1%
top 76.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3

Description

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages2 packages

NVDartifex/ghostscript< 10.03.1
Debianghostscript< 9.53.3~dfsg-7+deb11u7+3

🔴Vulnerability Details

3
OSV
CVE-2024-33870: An issue was discovered in Artifex Ghostscript before 102024-07-03
GHSA
GHSA-3xr3-vrm2-6jc7: An issue was discovered in Artifex Ghostscript before 102024-07-03
CVEList
CVE-2024-33870: An issue was discovered in Artifex Ghostscript before 102024-07-03

📋Vendor Advisories

3
Ubuntu
Ghostscript vulnerabilities2024-06-17
Red Hat
ghostscript: path traversal to arbitrary files if the current directory is in the permitted paths2024-05-16
Debian
CVE-2024-33870: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. There is path tra...2024
CVE-2024-33870 (MEDIUM CVSS 6.3) | An issue was discovered in Artifex | cvebase.io