CVE-2024-46954
published 2024-11-10CVE-2024-46954: An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.55%
42.3th percentile
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.05.0 | 10.05.0 |
| artifex | ghostscript | < 10.05.0 | 10.05.0 |
| artifex | ghostscript | < 10.04.0 | 10.04.0 |
| artifex | ghostscript | >= 0 < 10.04.0~dfsg-1 | 10.04.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.05.0~dfsg-1 | 10.05.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.04.0~dfsg-1 | 10.04.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.05.0~dfsg-1 | 10.05.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.14 | 9.50~dfsg-5ubuntu4.14 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.10 | 9.55.0~dfsg1-0ubuntu5.10 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.4 | 10.02.1~dfsg1-0ubuntu7.4 |
| debian | ghostscript | < ghostscript 10.04.0~dfsg-1 (forky) | ghostscript 10.04.0~dfsg-1 (forky) |
| debian | ghostscript | < ghostscript 10.05.0~dfsg-1 (forky) | ghostscript 10.05.0~dfsg-1 (forky) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Ghostscript: Mishandling of Overlong UTF-8 Encoding in Artifex Ghostscript's decode_utf8 Function
vendor_redhat·2025-04-26·CVSS 7.8
CVE-2025-46646 [HIGH] CWE-24 Ghostscript: Mishandling of Overlong UTF-8 Encoding in Artifex Ghostscript's decode_utf8 Function
Ghostscript: Mishandling of Overlong UTF-8 Encoding in Artifex Ghostscript's decode_utf8 Function
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.
A flaw was found in Artifex Ghostscript, specifically in the decode_utf8 function within base/gp_utf8.c. The issue arises from the mishandling of overlong UTF-8 encoding, which can lead to unexpected behavior when processing certain inputs. This flaw could allow an attacker to manipulate text encoding, potentially leading to incorrect processing of UTF-8 characters or unexpected application behavior, and exists because of an incomplete fix for CVE-2024-46954.
Mitigation: Mitigation for this issue is either not avail
Debian
CVE-2025-46646: ghostscript - In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles ...
vendor_debian·2025·CVSS 7.8
CVE-2025-46646 [HIGH] CVE-2025-46646: ghostscript - In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles ...
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 10.05.0~dfsg-1)
sid: resolved (fixed in 10.05.0~dfsg-1)
trixie: resolved (fixed in 10.05.0~dfsg-1)
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-11-12·CVSS 7.8
CVE-2024-46954 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-46951, CVE-2024-46953, CVE-2024-46955, CVE-2024-46956)
It was discovered that Ghostscript incorrectly handled parsing certain PDF
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10.
(CVE-2024-46952)
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this i
Red Hat
ghostscript: Directory Traversal in Ghostscript via Overlong UTF-8 Encoding
vendor_redhat·2024-11-10·CVSS 7.8
CVE-2024-46954 [HIGH] CWE-22 ghostscript: Directory Traversal in Ghostscript via Overlong UTF-8 Encoding
ghostscript: Directory Traversal in Ghostscript via Overlong UTF-8 Encoding
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
A flaw was found in Ghostscript/base/gp_utf8.c. This vulnerability allows directory traversal via overlong UTF-8 encoding, potentially leading to unauthorized access to filesystem directories.
Package: ghostscript (Red Hat Enterprise Linux 7) - Out of support scope
Package: gimp:flatpak/ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2024-46954: ghostscript - An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript ...
vendor_debian·2024·CVSS 7.8
CVE-2024-46954 [HIGH] CVE-2024-46954: ghostscript - An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript ...
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 10.04.0~dfsg-1)
sid: resolved (fixed in 10.04.0~dfsg-1)
trixie: resolved (fixed in 10.04.0~dfsg-1)
GHSA
GHSA-56g6-5g9j-wjc3: In Artifex Ghostscript before 10
ghsa_unreviewed·2025-04-26·CVSS 7.8
CVE-2025-46646 [HIGH] CWE-24 GHSA-56g6-5g9j-wjc3: In Artifex Ghostscript before 10
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.
OSV
CVE-2025-46646: In Artifex Ghostscript before 10
osv·2025-04-26·CVSS 7.8
CVE-2025-46646 [HIGH] CVE-2025-46646: In Artifex Ghostscript before 10
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.
OSV
ghostscript vulnerabilities
osv·2024-11-12·CVSS 7.8
CVE-2024-46951 [HIGH] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-46951, CVE-2024-46953, CVE-2024-46955, CVE-2024-46956)
It was discovered that Ghostscript incorrectly handled parsing certain PDF
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10.
(CVE-2024-46952)
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service
GHSA
GHSA-2v5c-72gh-q5f7: An issue was discovered in decode_utf8 in base/gp_utf8
ghsa_unreviewed·2024-11-11
CVE-2024-46954 [HIGH] CWE-22 GHSA-2v5c-72gh-q5f7: An issue was discovered in decode_utf8 in base/gp_utf8
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
OSV
CVE-2024-46954: An issue was discovered in decode_utf8 in base/gp_utf8
osv·2024-11-10·CVSS 7.8
CVE-2024-46954 [HIGH] CVE-2024-46954: An issue was discovered in decode_utf8 in base/gp_utf8
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-10
Published