PT-2024-35961 · Unknown+3 · Ghostscript+3

Published

2024-12-03

·

Updated

2025-08-26

·

CVE-2024-53863

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Synapse versions prior to 1.120.1
Description: Synapse is an open-source Matrix homeserver. Enabling the dynamic thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing. This significantly expands the attack surface in a historically vulnerable area, presenting a risk that far outweighs the benefit, particularly since these formats are rarely used on the open web or within the Matrix ecosystem. The issue is addressed by restricting thumbnail generation to images in widely used formats: PNG, JPEG, GIF, and WebP.
Recommendations: For Synapse versions prior to 1.120.1, update to version 1.120.1 to restrict thumbnail generation to widely used image formats. As a temporary workaround, consider disabling the dynamic thumbnails option until a patch is available. Ensure any image codecs and helper programs, such as Ghostscript, are patched against security vulnerabilities. Uninstall unused image decoder libraries and helper programs, such as Ghostscript, from the system environment that Synapse is running in.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-53863
GHSA-VP6V-WHFM-RV3G
OPENSUSE-SU-2024:14541-1
USN-7444-1

Affected Products

Ghostscript
Linuxmint
Synapse
Ubuntu