PT-2024-7981 · Artifex+5 · Artifex Ghostscript+5

Published

2024-09-16

·

Updated

2026-05-13

·

CVE-2024-46955

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions prior to 10.04.0
Description An issue was discovered in the psi/zcolor.c component of Artifex Ghostscript, related to an out-of-bounds read when reading color in Indexed color space. This can lead to a denial of service.
Recommendations For versions prior to 10.04.0, update to version 10.04.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Indexed color space in psi/zcolor.c until a patch is available.

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2024-09494
CVE-2024-46955
DLA-3965-1
DSA-5808-1
MGASA-2024-0326
OESA-2024-2355
OESA-2024-2356
OESA-2024-2359
OESA-2024-2412
OESA-2024-2413
OPENSUSE-SU-2024:14423-1
OPENSUSE-SU-2024_3941-1
SUSE-SU-2024:3941-1
SUSE-SU-2024:3942-1
USN-7103-1
USN-7138-1

Affected Products

Artifex Ghostscript
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu