PT-2024-4558 · Artifex+9 · Artifex Ghostscript+9
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ghostscript versions prior to 10.03.1
Description
A format string injection flaw exists in the uniprint device of Ghostscript, a PostScript and PDF interpreter. The issue occurs because the device allows users to pass string fragments as options—specifically
upWriteComponentCommands and upYMoveCommand—which are then processed as format strings by the gp fprintf() and gs snprintf() functions without proper restriction. This allows an attacker to inject arbitrary format specifiers (such as %n, %s, and %x), leading to memory corruption, data leakage from the stack, and a bypass of the SAFER sandbox. The SAFER sandbox is a security mechanism designed to prevent PostScript code from executing dangerous commands or accessing arbitrary files. Successful exploitation can result in a denial of service or the execution of arbitrary code within the context of the Ghostscript process, potentially leading to full system compromise if the software is running with elevated privileges.Recommendations
Upgrade to version 10.03.1 or later.
As a temporary mitigation, disable Ghostscript delegates and restrict the processing of PDF and PS files.
Isolate servers used for document processing to minimize the risk of exploitation.
Exploit
Fix
RCE
DoS
Protection Mechanism Failure
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Artifex Ghostscript
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu