REDHAT-BUG-2325044: Medium severity ghostscript vulnerability
Published Nov 10, 2024
·Updated
An issue was discovered in decodeutf8 in base/gputf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
Affected Software
1 affected component
Artifex ghostscript<10.04.0
Event History
Nov 10, 2024
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2325044?
REDHAT-BUG-2325044 is considered to have a medium severity due to the possibility of directory traversal exploitation.
2
How do I fix REDHAT-BUG-2325044?
To fix REDHAT-BUG-2325044, upgrade Artifex Ghostscript to version 10.04.0 or later.
3
What is the impact of REDHAT-BUG-2325044?
The impact of REDHAT-BUG-2325044 is the potential for attackers to exploit overlong UTF-8 encoding for directory traversal.
4
Which versions of Ghostscript are affected by REDHAT-BUG-2325044?
All versions of Artifex Ghostscript prior to 10.04.0 are affected by REDHAT-BUG-2325044.
5
Is there a workaround for REDHAT-BUG-2325044?
There is no known workaround for REDHAT-BUG-2325044; upgrading is the recommended solution.