PT-2024-4558 · Artifex+9 · Artifex Ghostscript+9
Alchemist
·
Published
2024-05-09
·
Updated
2026-02-09
·
CVE-2024-29510
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Artifex Ghostscript versions prior to 10.03.1
Description
The vulnerability in Artifex Ghostscript is related to a format string injection in the uniprint device, which can lead to memory corruption and allow an attacker to bypass the -dSAFER sandbox, executing code remotely. This vulnerability affects versions of Ghostscript prior to 10.03.1. The exploitation of this vulnerability can result in remote code execution, allowing attackers to execute arbitrary code on the vulnerable system. There are reports of this vulnerability being exploited in the wild, with attackers using EPS (PostScript) files camouflaged as JPG (image) files to gain shell access to vulnerable systems.
Recommendations
To resolve the issue, update Artifex Ghostscript to version 10.03.1 or later. For versions prior to 10.03.1, consider disabling the uniprint device or restricting its use until the update can be applied. Additionally, monitor your systems for any signs of exploitation and consider implementing additional security measures to prevent remote code execution attacks.
Exploit
Fix
RCE
DoS
Buffer Overflow
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Artifex Ghostscript
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu