CVE-2024-33870
published 2024-07-03CVE-2024-33870: An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current…
PriorityP434medium6.3CVSS 3.1
AVAACLPRNUINSUCLILAL
EPSS
0.52%
40.4th percentile
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.03.1 | 10.03.1 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u7 | 9.53.3~dfsg-7+deb11u7 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u4 | 10.0.0~dfsg-11+deb12u4 |
| artifex | ghostscript | >= 0 < 10.03.1~dfsg~git20240518-1 | 10.03.1~dfsg~git20240518-1 |
| artifex | ghostscript | >= 0 < 10.03.1~dfsg~git20240518-1 | 10.03.1~dfsg~git20240518-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.12 | 9.50~dfsg-5ubuntu4.12 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.7 | 9.55.0~dfsg1-0ubuntu5.7 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.1 | 10.02.1~dfsg1-0ubuntu7.1 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u4 (bookworm) |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-06-17·CVSS 5.5
CVE-2024-33871 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript did not properly restrict eexec
seeds to those specified by the Type 1 Font Format standard when
SAFER mode is used. An attacker could use this issue to bypass SAFER
restrictions and cause unspecified impact. (CVE-2023-52722)
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.10.
Thomas Rinsma discovered that Ghostscript did not prevent changes to
uniprint device argument strings after SAFER is activated, resulting
in a format-string vulnerability. An attacker could possibly use this
to execute arbitrary code. (CVE-2024-29510)
Zdenek Hutyra discovered that Ghostscript did not properly perform
path reduction when validating paths. An a
Red Hat
ghostscript: path traversal to arbitrary files if the current directory is in the permitted paths
vendor_redhat·2024-05-16·CVSS 6.3
CVE-2024-33870 [MEDIUM] CWE-23 ghostscript: path traversal to arbitrary files if the current directory is in the permitted paths
ghostscript: path traversal to arbitrary files if the current directory is in the permitted paths
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
A flaw was found in Ghostscript. When the `gp_validate_path_len` function validates a path, it distinguishes between absolute and relative paths. In the case of relative paths, it will check the path with and without the current-directory-prefix ("foo" and "./foo"). This does not take into account paths with a parent-directory-prefix. Therefore, a path like "../../foo" is also tested a
Debian
CVE-2024-33870: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. There is path tra...
vendor_debian·2024·CVSS 6.3
CVE-2024-33870 [MEDIUM] CVE-2024-33870: ghostscript - An issue was discovered in Artifex Ghostscript before 10.03.1. There is path tra...
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u4)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u7)
forky: resolved (fixed in 10.03.1~dfsg~git20240518-1)
sid: resolved (fixed in 10.03.1~dfsg~git20240518-1)
trixie: resolved (fixed in 10.03.1~dfsg~git20240518-1)
OSV
CVE-2024-33870: An issue was discovered in Artifex Ghostscript before 10
osv·2024-07-03·CVSS 6.3
CVE-2024-33870 [MEDIUM] CVE-2024-33870: An issue was discovered in Artifex Ghostscript before 10
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
GHSA
GHSA-3xr3-vrm2-6jc7: An issue was discovered in Artifex Ghostscript before 10
ghsa_unreviewed·2024-07-03
CVE-2024-33870 [MEDIUM] CWE-22 GHSA-3xr3-vrm2-6jc7: An issue was discovered in Artifex Ghostscript before 10
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
OSV
ghostscript vulnerabilities
osv·2024-06-17·CVSS 5.5
CVE-2023-52722 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript did not properly restrict eexec
seeds to those specified by the Type 1 Font Format standard when
SAFER mode is used. An attacker could use this issue to bypass SAFER
restrictions and cause unspecified impact. (CVE-2023-52722)
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.10.
Thomas Rinsma discovered that Ghostscript did not prevent changes to
uniprint device argument strings after SAFER is activated, resulting
in a format-string vulnerability. An attacker could possibly use this
to execute arbitrary code. (CVE-2024-29510)
Zdenek Hutyra discovered that Ghostscript did not properly perform
path reduction when validating paths. An attacker could use this to
access file locations outside of those all
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-03
Published