PT-2024-5032 · Artifex+6 · Artifex Ghostscript+6

Thomas Rinsma

·

Published

2024-01-24

·

Updated

2025-07-08

·

CVE-2024-29508

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Artifex Ghostscript versions prior to 10.03.0 Artifex Ghostscript versions prior to 10.0.3.0
Description: The issue is related to a heap-based pointer disclosure in the pdf base font alloc() function, observable in a constructed BaseFont name. This is caused by a buffer overflow due to incorrect scaling of the pointer (".F" PRI INTPTR). Exploitation of this issue may allow a remote attacker to execute arbitrary code or cause a denial of service.
Recommendations: For versions prior to 10.03.0, update to version 10.03.0 or later. For versions prior to 10.0.3.0, update to version 10.0.3.0 or later. As a temporary workaround, consider restricting access to the pdf base font alloc() function until a patch is available.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-13477
ALT-PU-2024-14136
ALT-PU-2024-14302
BDU:2024-05559
CVE-2024-29508
DLA-3931-1
DSA-5760-1
OESA-2024-2159
OESA-2024-2160
OESA-2024-2161
OESA-2024-2162
OESA-2024-2163
OPENSUSE-SU-2024_2627-1
ROSA-SA-2025-2622
ROSA-SA-2025-2623
SUSE-SU-2024:2547-1
SUSE-SU-2024:2627-1
SUSE-SU-2024_2547-1
SUSE-SU-2024_2627-1
USN-6897-1
USN-7623-1

Affected Products

Alt Linux
Artifex Ghostscript
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu