PT-2024-35961 · Unknown+3 · Ghostscript+3
Published
2024-12-03
·
Updated
2025-08-26
·
CVE-2024-53863
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Synapse versions prior to 1.120.1
Description:
Synapse is an open-source Matrix homeserver. Enabling the
dynamic thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing. This significantly expands the attack surface in a historically vulnerable area, presenting a risk that far outweighs the benefit, particularly since these formats are rarely used on the open web or within the Matrix ecosystem. The issue is addressed by restricting thumbnail generation to images in widely used formats: PNG, JPEG, GIF, and WebP.Recommendations:
For Synapse versions prior to 1.120.1, update to version 1.120.1 to restrict thumbnail generation to widely used image formats.
As a temporary workaround, consider disabling the
dynamic thumbnails option until a patch is available.
Ensure any image codecs and helper programs, such as Ghostscript, are patched against security vulnerabilities.
Uninstall unused image decoder libraries and helper programs, such as Ghostscript, from the system environment that Synapse is running in.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscript
Linuxmint
Synapse
Ubuntu