PT-2024-5030 · Artifex+4 · Artifex Ghostscript+4
Thomas Rinsma
·
Published
2024-01-24
·
Updated
2025-02-14
·
CVE-2024-29509
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Artifex Ghostscript versions prior to 10.03.0
Description:
The issue is related to a heap-based overflow when the
PDFPassword parameter has a 000 byte in the middle, which can be exploited by a remote attacker to cause a denial of service.Recommendations:
For versions prior to 10.03.0, update to version 10.03.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
PDFPassword parameter to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Artifex Ghostscript
Astra Linux
Linuxmint
Ubuntu