CVE-2024-29507: Buffer Overflow
Published Jul 3, 2024
·Updated
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
Affected Software
2 affected componentsFixes available
debian/ghostscript<=10.0.0~dfsg-11+deb12u4
9.53.3~dfsg-7+deb11u710.0.0~dfsg-11+deb12u510.03.1~dfsg-2
Artifex GhostScript<10.03.0
Remediation
Event History
Jul 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
Description
Data Sourced
via NVD·07:15 PM
SeverityWeakness
Sep 13, 2024
Data Sourced
via Ubuntu·03:09 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29507?
CVE-2024-29507 is classified as a high severity vulnerability due to its potential for exploitation through a stack-based buffer overflow.
2
How do I fix CVE-2024-29507?
To mitigate CVE-2024-29507, update to Ghostscript version 10.03.1~dfsg-2 or higher.
3
What software is affected by CVE-2024-29507?
CVE-2024-29507 affects Ghostscript versions prior to 10.03.0, including specific older versions listed in the Debian package details.
4
What are the potential impacts of exploiting CVE-2024-29507?
Exploitation of CVE-2024-29507 may result in arbitrary code execution, potentially compromising system integrity.
5
Is CVE-2024-29507 specific to any operating system?
CVE-2024-29507 primarily affects Debian-based systems using vulnerable versions of the Ghostscript package.