CVE-2024-29507: Buffer Overflow
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 9.53.3~dfsg-7+deb11u7Fixed in 10.0.0~dfsg-11+deb12u5Fixed in 10.03.1~dfsg-2 - Upgrade
Upgrade
Artifex Ghostscriptto a version that resolves this vulnerability.Fixed in 10.03.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29507?
CVE-2024-29507 is classified as a high severity vulnerability due to its potential for exploitation through a stack-based buffer overflow.
How do I fix CVE-2024-29507?
To mitigate CVE-2024-29507, update to Ghostscript version 10.03.1~dfsg-2 or higher.
What software is affected by CVE-2024-29507?
CVE-2024-29507 affects Ghostscript versions prior to 10.03.0, including specific older versions listed in the Debian package details.
What are the potential impacts of exploiting CVE-2024-29507?
Exploitation of CVE-2024-29507 may result in arbitrary code execution, potentially compromising system integrity.
Is CVE-2024-29507 specific to any operating system?
CVE-2024-29507 primarily affects Debian-based systems using vulnerable versions of the Ghostscript package.