CVE-2024-46956

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*

History

14 Nov 2024, 20:39

Type Values Removed Values Added
First Time Suse linux Enterprise Server For Sap
Suse linux Enterprise Server
Artifex ghostscript
Suse linux Enterprise High Performance Computing
Artifex
Suse
Debian debian Linux
Debian
CPE cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
References () https://bugs.ghostscript.com/show_bug.cgi?id=707895 - () https://bugs.ghostscript.com/show_bug.cgi?id=707895 - Permissions Required
References () https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca - () https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca - Patch
References () https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html - () https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html - Product
References () https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/ - () https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/ - Third Party Advisory

12 Nov 2024, 20:35

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en psi/zfile.c en Artifex Ghostscript anterior a la versión 10.04.0. El acceso a datos fuera de los límites en filenameforall puede provocar la ejecución de código arbitrario.

10 Nov 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-10 22:15

Updated : 2024-11-14 20:39


NVD link : CVE-2024-46956

Mitre link : CVE-2024-46956

CVE.ORG link : CVE-2024-46956


JSON object : View

Products Affected

debian

  • debian_linux

suse

  • linux_enterprise_server_for_sap
  • linux_enterprise_high_performance_computing
  • linux_enterprise_server

artifex

  • ghostscript
CWE
CWE-125

Out-of-bounds Read