CVE-2024-46956
published 2024-11-10CVE-2024-46956: An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.39%
31.1th percentile
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.04.0 | 10.04.0 |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u9 | 9.53.3~dfsg-7+deb11u9 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u6 | 10.0.0~dfsg-11+deb12u6 |
| artifex | ghostscript | >= 0 < 10.04.0~dfsg-1 | 10.04.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.04.0~dfsg-1 | 10.04.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.14 | 9.50~dfsg-5ubuntu4.14 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.10 | 9.55.0~dfsg1-0ubuntu5.10 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.4 | 10.02.1~dfsg1-0ubuntu7.4 |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u6 (bookworm) |
| suse | linux_enterprise_high_performance_computing | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server_for_sap | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Ghostscript) — CVE-2024-46956
vendor_oracle·2025-07-15·CVSS 7.8
CVE-2024-46956 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Ghostscript) — CVE-2024-46956
Oracle Oracle Communications Risk Matrix: Platform (Ghostscript) vulnerability
CVE: CVE-2024-46956
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-12-05
CVE-2024-46951 Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2024-11-12·CVSS 7.8
CVE-2024-46954 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-46951, CVE-2024-46953, CVE-2024-46955, CVE-2024-46956)
It was discovered that Ghostscript incorrectly handled parsing certain PDF
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10.
(CVE-2024-46952)
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this i
Red Hat
ghostscript: Out-of-Bounds Data Access in Ghostscript Leads to Arbitrary Code Execution
vendor_redhat·2024-11-10·CVSS 7.8
CVE-2024-46956 [HIGH] CWE-125 ghostscript: Out-of-Bounds Data Access in Ghostscript Leads to Arbitrary Code Execution
ghostscript: Out-of-Bounds Data Access in Ghostscript Leads to Arbitrary Code Execution
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
A flaw was found in Artifex Ghostscript's psi/zfile.c component. This vulnerability allows arbitrary code execution via out-of-bounds data access.
Package: ghostscript (Red Hat Enterprise Linux 7) - Out of support scope
Package: gimp:flatpak/ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2024-46956: ghostscript - An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Ou...
vendor_debian·2024·CVSS 7.8
CVE-2024-46956 [HIGH] CVE-2024-46956: ghostscript - An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Ou...
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u6)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u9)
forky: resolved (fixed in 10.04.0~dfsg-1)
sid: resolved (fixed in 10.04.0~dfsg-1)
trixie: resolved (fixed in 10.04.0~dfsg-1)
OSV
ghostscript vulnerabilities
osv·2024-11-12·CVSS 7.8
CVE-2024-46951 [HIGH] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-46951, CVE-2024-46953, CVE-2024-46955, CVE-2024-46956)
It was discovered that Ghostscript incorrectly handled parsing certain PDF
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10.
(CVE-2024-46952)
It was discovered that Ghostscript incorrectly handled parsing certain PS
files. An attacker could use this issue to cause Ghostscript to crash,
resulting in a denial of service
GHSA
GHSA-jrvf-vccr-mvp6: An issue was discovered in psi/zfile
ghsa_unreviewed·2024-11-11
CVE-2024-46956 [HIGH] CWE-125 GHSA-jrvf-vccr-mvp6: An issue was discovered in psi/zfile
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
OSV
CVE-2024-46956: An issue was discovered in psi/zfile
osv·2024-11-10·CVSS 7.8
CVE-2024-46956 [HIGH] CVE-2024-46956: An issue was discovered in psi/zfile
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.ghostscript.com/show_bug.cgi?id=707895https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6cahttps://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.htmlhttps://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/https://lists.debian.org/debian-lts-announce/2024/11/msg00023.html
2024-11-10
Published