REDHAT-BUG-2325045: Integer Overflow
Published Nov 10, 2024
·Updated
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
Affected Software
1 affected component
Artifex ghostscript<10.04.0
Event History
Nov 10, 2024
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2325045?
REDHAT-BUG-2325045 has a critical severity due to the potential for code execution and path traversal.
2
How do I fix REDHAT-BUG-2325045?
To fix REDHAT-BUG-2325045, upgrade to Ghostscript version 10.04.0 or higher.
3
What causes REDHAT-BUG-2325045?
REDHAT-BUG-2325045 is caused by an integer overflow when parsing the filename format string in Ghostscript.
4
What are the risks associated with REDHAT-BUG-2325045?
The risks associated with REDHAT-BUG-2325045 include path truncation, path traversal, and possible remote code execution.
5
Which versions of Ghostscript are affected by REDHAT-BUG-2325045?
All versions of Ghostscript prior to 10.04.0 are affected by REDHAT-BUG-2325045.