CVE-2024-46956

A

n issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

Configurations

Configuration 1 (hide)

cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*

History

03 Nov 2025, 23:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/11/msg00023.html -

14 Nov 2024, 20:39

Type Values Removed Values Added
First Time Suse linux Enterprise Server For Sap
Debian debian Linux
Artifex ghostscript
Suse
Artifex
Debian
Suse linux Enterprise Server
Suse linux Enterprise High Performance Computing
References () https://bugs.ghostscript.com/show_bug.cgi?id=707895 - () https://bugs.ghostscript.com/show_bug.cgi?id=707895 - Permissions Required
References () https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca - () https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca - Patch
References () https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html - () https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html - Product
References () https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/ - () https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/ - Third Party Advisory
CPE cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*

12 Nov 2024, 20:35

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en psi/zfile.c en Artifex Ghostscript anterior a la versión 10.04.0. El acceso a datos fuera de los límites en filenameforall puede provocar la ejecución de código arbitrario.

10 Nov 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-10 22:15

Updated : 2025-11-03 23:16


NVD link : CVE-2024-46956

Mitre link : CVE-2024-46956

CVE.ORG link : CVE-2024-46956


JSON object : View

CWE
CWE-125

Out-of-bounds Read