CVE-2024-29509: High severity ghostscript vulnerability
Published Jul 3, 2024
·Updated
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
Affected Software
2 affected componentsFixes available
debian/ghostscript<=10.0.0~dfsg-11+deb12u4
9.53.3~dfsg-7+deb11u710.0.0~dfsg-11+deb12u510.03.1~dfsg-2
Artifex GhostScript<10.03.0
Remediation
Event History
Jul 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·03:09 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29509?
CVE-2024-29509 is classified as a high-severity vulnerability due to its potential to cause heap-based overflow.
2
How do I fix CVE-2024-29509?
To fix CVE-2024-29509, update Ghostscript to version 10.03.1 or later.
3
Which versions of Ghostscript are affected by CVE-2024-29509?
Affected versions include all versions of Ghostscript prior to 10.03.0.
4
What type of vulnerability is CVE-2024-29509?
CVE-2024-29509 is a heap overflow vulnerability that can be triggered by a specific PDF password formatting.
5
Is there a patch available for CVE-2024-29509?
Yes, a patch is available in Ghostscript version 10.03.1 and later.