PT-2024-4560 · Unknown+10 · Ghostscript+10
Zhutyra
·
Published
2024-04-21
·
Updated
2026-03-29
·
CVE-2024-33871
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Ghostscript versions prior to 10.03.1
Description:
The issue exists due to insufficient input validation in the contrib/opvp/gdevopvp.c component of the Ghostscript interpreter. This can be exploited by a remote attacker using a specially crafted PostScript file, potentially allowing arbitrary code execution. The vulnerability is related to the Driver parameter for opvp devices, which can have an arbitrary name for a dynamic library, and this library is then loaded.
Recommendations:
For Ghostscript versions prior to 10.03.1, update to version 10.03.1 or later to resolve the issue.
As a temporary workaround, consider restricting the use of custom Driver libraries for opvp devices to minimize the risk of exploitation.
Fix
Code Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Ghostscript
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu