CVE-2024-29506: Buffer Overflow
Published Jul 3, 2024
·Updated
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfiapplyfilter() function via a long PDF filter name.
Affected Software
2 affected componentsFixes available
debian/ghostscript<=10.0.0~dfsg-11+deb12u4
9.53.3~dfsg-7+deb11u710.0.0~dfsg-11+deb12u510.03.1~dfsg-2
Artifex GhostScript<10.03.0
Remediation
Event History
Jul 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 17, 2024
Data Sourced
via Ubuntu·03:09 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29506?
CVE-2024-29506 is classified as a stack-based buffer overflow vulnerability that can lead to potential code execution.
2
How do I fix CVE-2024-29506?
To fix CVE-2024-29506, upgrade Ghostscript to version 10.03.1~dfsg-2 or later.
3
Which versions of Ghostscript are affected by CVE-2024-29506?
Ghostscript versions before 10.03.0, including 9.53.3~dfsg-7+deb11u7 and 10.0.0~dfsg-11+deb12u4, are affected by CVE-2024-29506.
4
What impact does CVE-2024-29506 have on systems using Ghostscript?
CVE-2024-29506 can allow attackers to execute arbitrary code on systems running vulnerable versions of Ghostscript.
5
Is there a public exploit for CVE-2024-29506?
As of the latest updates, there are no known public exploits specifically targeting CVE-2024-29506.