PT-2024-4558 · Artifex+9 · Artifex Ghostscript+9

Alchemist

·

Published

2024-05-09

·

Updated

2026-02-09

·

CVE-2024-29510

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions prior to 10.03.1
Description The vulnerability in Artifex Ghostscript is related to a format string injection in the uniprint device, which can lead to memory corruption and allow an attacker to bypass the -dSAFER sandbox, executing code remotely. This vulnerability affects versions of Ghostscript prior to 10.03.1. The exploitation of this vulnerability can result in remote code execution, allowing attackers to execute arbitrary code on the vulnerable system. There are reports of this vulnerability being exploited in the wild, with attackers using EPS (PostScript) files camouflaged as JPG (image) files to gain shell access to vulnerable systems.
Recommendations To resolve the issue, update Artifex Ghostscript to version 10.03.1 or later. For versions prior to 10.03.1, consider disabling the uniprint device or restricting its use until the update can be applied. Additionally, monitor your systems for any signs of exploitation and consider implementing additional security measures to prevent remote code execution attacks.

Exploit

Fix

RCE

DoS

Buffer Overflow

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

ALSA-2024:6197
ALT-PU-2024-13477
ALT-PU-2024-14136
ALT-PU-2024-14302
BDU:2024-05062
CVE-2024-29510
DSA-5692-1
INFSA-2024_6197
MGASA-2024-0192
OESA-2024-2159
OESA-2024-2162
OESA-2024-2163
OPENSUSE-SU-2024:14090-1
OPENSUSE-SU-2024_2292-1
RHSA-2024:6197
RHSA-2024:6466
RHSA-2024_6197
SUSE-SU-2024:2276-1
SUSE-SU-2024:2292-1
SUSE-SU-2024_2276-1
SUSE-SU-2024_2292-1
USN-6835-1

Affected Products

Alt Linux
Almalinux
Artifex Ghostscript
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu