CVE-2024-29508: Low severity Artifex GhostScript vulnerability
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdfbasefontalloc.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 10.0.0~dfsg-11+deb12u5Fixed in 10.03.1~dfsg-2 - Upgrade
Upgrade
Artifex Ghostscriptto a version that resolves this vulnerability.Fixed in 10.03.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29508?
CVE-2024-29508 is classified as a high severity vulnerability due to the potential for sensitive data disclosure.
How do I fix CVE-2024-29508?
To fix CVE-2024-29508, update Ghostscript to version 10.03.1 or later.
What is the affected software for CVE-2024-29508?
CVE-2024-29508 affects versions of Artifex Ghostscript prior to 10.03.0.
What are the implications of CVE-2024-29508?
The implications of CVE-2024-29508 include the potential for unauthorized access to sensitive data through pointer disclosure.
Is there a known exploit for CVE-2024-29508?
As of now, there are no publicly known exploits for CVE-2024-29508.