CVE-2024-46955: Medium severity ghostscript vulnerability
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46955?
CVE-2024-46955 is classified as a high-severity vulnerability due to its potential for causing out-of-bounds read errors.
How do I fix CVE-2024-46955?
To fix CVE-2024-46955, update to Ghostscript version 10.04.0 or later, ensuring your installation is not below 9.53.3~dfsg-7+deb11u9.
Who is affected by CVE-2024-46955?
CVE-2024-46955 affects users of Ghostscript versions prior to 10.04.0, particularly those on Debian and SUSE Linux distributions.
What types of software are impacted by CVE-2024-46955?
CVE-2024-46955 impacts Artifex Ghostscript and related Debian and SUSE software packages.
Is a workaround available for CVE-2024-46955?
Currently, there is no official workaround for CVE-2024-46955, and updating to the patched version is the recommended mitigation.