First published: Sun Nov 10 2024(Updated: )
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ghostscript | 9.53.3~dfsg-7+deb11u7 9.53.3~dfsg-7+deb11u9 10.0.0~dfsg-11+deb12u6 10.04.0~dfsg-2 | |
Ghostscript | <10.04.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46954 has been classified as a potential security vulnerability due to directory traversal risks.
To fix CVE-2024-46954, upgrade to Ghostscript version 10.04.0 or later.
Ghostscript versions prior to 10.04.0 are affected by CVE-2024-46954.
Exploitation of CVE-2024-46954 may allow attackers to perform directory traversal attacks.
More information on CVE-2024-46954 can be found in the Ghostscript issue tracker and changelogs.