PT-2024-5149 · Artifex+3 · Artifex Ghostscript+3

Thomas Rinsma

·

Published

2024-07-03

·

Updated

2025-10-28

·

CVE-2024-29511

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions prior to 10.03.1
Description The Ghostscript software suite contains a directory traversal issue when using Tesseract for Optical Character Recognition (OCR). This allows for arbitrary file reading and writing of error messages to arbitrary files through the OCRLanguage parameter. Specifically, exploitation can occur via the debug file and user patterns file parameters. The API endpoints potentially involved are those utilizing OCR functionality. The vulnerable parameters are debug file and user patterns file.
Recommendations Versions prior to 10.03.1 should be updated to version 10.03.1 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-05696
CVE-2024-29511
USN-6897-1

Affected Products

Artifex Ghostscript
Debian
Linuxmint
Ubuntu