PT-2024-6395 · Artifex+9 · Artifex Ghostscript+9
Zhutyra
·
Published
2024-05-09
·
Updated
2024-11-07
·
CVE-2024-33869
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Artifex Ghostscript versions prior to 10.03.1
Description
The issue is related to path reduction in the base/gpmisc.c file of Ghostscript, allowing for path traversal and command execution via a crafted PostScript document. This can lead to restrictions on the use of %pipe% being bypassed, potentially enabling arbitrary code execution. The vulnerability is caused by incorrect input validation, which could allow a remote attacker to execute arbitrary code.
Recommendations
For versions prior to 10.03.1, update to version 10.03.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the %pipe% command in PostScript documents to minimize the risk of exploitation. Avoid using the
output filename parameter with crafted filenames, such as aa/../%pipe%command#, until the issue is resolved.Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Artifex Ghostscript
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu