CVE-2024-29508: Low severity ghostscript vulnerability
Published Jul 3, 2024
·Updated
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdfbasefontalloc.
Affected Software
2 affected componentsFixes available
debian/ghostscript<=9.53.3~dfsg-7+deb11u7, <=10.0.0~dfsg-11+deb12u4
10.0.0~dfsg-11+deb12u510.03.1~dfsg-2
Artifex GhostScript<10.03.0
Remediation
Event History
Jul 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 13, 2024
Data Sourced
via Ubuntu·03:09 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29508?
CVE-2024-29508 is classified as a high severity vulnerability due to the potential for sensitive data disclosure.
2
How do I fix CVE-2024-29508?
To fix CVE-2024-29508, update Ghostscript to version 10.03.1 or later.
3
What is the affected software for CVE-2024-29508?
CVE-2024-29508 affects versions of Artifex Ghostscript prior to 10.03.0.
4
What are the implications of CVE-2024-29508?
The implications of CVE-2024-29508 include the potential for unauthorized access to sensitive data through pointer disclosure.
5
Is there a known exploit for CVE-2024-29508?
As of now, there are no publicly known exploits for CVE-2024-29508.