ZeroHour

CVE-2024-46953

CVSS 3.1
7.8 high
EPSS
<1%p32
Published
()
Modified
Description

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

Vendors
artifexdebiansuse
Products
ghostscript, debian linux, linux enterprise high performance computing, linux enterprise server, linux enterprise server for sap
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.