CVE-2024-46956

CWE-125Out-of-bounds Read10 documents8 sources
Severity
7.8HIGH
EPSS
0.3%
top 44.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateJul 15

Description

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDartifex/ghostscript< 10.04.0
Debianghostscript< 9.53.3~dfsg-7+deb11u9+3
Ubuntughostscript< 9.50~dfsg-5ubuntu4.14+2

Also affects: Debian Linux 12.0, Linux Enterprise 12

Patches

🔴Vulnerability Details

4
OSV
ghostscript vulnerabilities2024-11-12
GHSA
GHSA-jrvf-vccr-mvp6: An issue was discovered in psi/zfile2024-11-11
CVEList
CVE-2024-46956: An issue was discovered in psi/zfile2024-11-10
OSV
CVE-2024-46956: An issue was discovered in psi/zfile2024-11-10

📋Vendor Advisories

5
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Ghostscript) — CVE-2024-469562025-07-15
Ubuntu
Ghostscript vulnerabilities2024-12-05
Ubuntu
Ghostscript vulnerabilities2024-11-12
Red Hat
ghostscript: Out-of-Bounds Data Access in Ghostscript Leads to Arbitrary Code Execution2024-11-10
Debian
CVE-2024-46956: ghostscript - An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Ou...2024