216.73.216.197

CVE-2024-46953

· Published 10/11/2024 22:15 · Modified 14/11/2024 02:01

Labels: CVE-2024-46953 2024-11-10CVE-2024-46953CWE-190[email protected]

Essential information

Published
10/11/2024 22:15
Modified
14/11/2024 02:01
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
artifex / ghostscript cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
debian / debian linux cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
suse / linux enterprise high performance computing cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
suse / linux enterprise server cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
suse / linux enterprise server cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
suse / linux enterprise server cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
suse / linux enterprise server for sap cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*

References