cbcvebase.
CVE-2024-46953
published 2024-11-10

CVE-2024-46953: An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output…

PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.39%
31.1th percentile
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

Affected

13 ranges
VendorProductVersion rangeFixed in
artifexghostscript< 10.04.010.04.0
artifexghostscript>= 0 < 9.53.3~dfsg-7+deb11u99.53.3~dfsg-7+deb11u9
artifexghostscript>= 0 < 10.0.0~dfsg-11+deb12u610.0.0~dfsg-11+deb12u6
artifexghostscript>= 0 < 10.04.0~dfsg-110.04.0~dfsg-1
artifexghostscript>= 0 < 10.04.0~dfsg-110.04.0~dfsg-1
artifexghostscript>= 0 < 9.50~dfsg-5ubuntu4.149.50~dfsg-5ubuntu4.14
artifexghostscript>= 0 < 9.55.0~dfsg1-0ubuntu5.109.55.0~dfsg1-0ubuntu5.10
artifexghostscript>= 0 < 10.02.1~dfsg1-0ubuntu7.410.02.1~dfsg1-0ubuntu7.4
debiandebian_linux
debianghostscript< ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm)ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm)
suselinux_enterprise_high_performance_computing
suselinux_enterprise_server
suselinux_enterprise_server_for_sap

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.