CVE-2024-46954: Path Traversal
Published Nov 10, 2024
·Updated
An issue was discovered in decodeutf8 in base/gputf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
Affected Software
2 affected componentsFixes available
Artifex GhostScript<10.04.0
debian/ghostscript
9.53.3~dfsg-7+deb11u79.53.3~dfsg-7+deb11u910.0.0~dfsg-11+deb12u610.05.0~dfsg-1
Remediation
Event History
Nov 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 16, 2024
Data Sourced
via Ubuntu·06:56 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-46954?
CVE-2024-46954 has been classified as a potential security vulnerability due to directory traversal risks.
2
How do I fix CVE-2024-46954?
To fix CVE-2024-46954, upgrade to Ghostscript version 10.04.0 or later.
3
Which versions of Ghostscript are affected by CVE-2024-46954?
Ghostscript versions prior to 10.04.0 are affected by CVE-2024-46954.
4
What can happen if CVE-2024-46954 is exploited?
Exploitation of CVE-2024-46954 may allow attackers to perform directory traversal attacks.
5
Where can I find more information on CVE-2024-46954?
More information on CVE-2024-46954 can be found in the Ghostscript issue tracker and changelogs.