CVE-2024-46951

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*

History

14 Nov 2024, 02:13

Type Values Removed Values Added
First Time Suse linux Enterprise High Performance Computing
Suse linux Enterprise Server
Artifex ghostscript
Artifex
Debian
Suse linux Enterprise Server For Sap
Debian debian Linux
Suse
CPE cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
References () https://bugs.ghostscript.com/show_bug.cgi?id=707991 - () https://bugs.ghostscript.com/show_bug.cgi?id=707991 - Permissions Required
References () https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f49812186baa7d1362880673408a6fbe8719b4f8 - () https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f49812186baa7d1362880673408a6fbe8719b4f8 - Patch
References () https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html - () https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html - Product
References () https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/ - () https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/ - Third Party Advisory

12 Nov 2024, 21:35

Type Values Removed Values Added
CWE CWE-824
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en psi/zcolor.c en Artifex Ghostscript anterior a la versión 10.04.0. Un puntero de implementación sin marcar en el espacio de color Pattern podría provocar la ejecución de código arbitrario.

10 Nov 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-10 21:15

Updated : 2024-11-14 02:13


NVD link : CVE-2024-46951

Mitre link : CVE-2024-46951

CVE.ORG link : CVE-2024-46951


JSON object : View

Products Affected

suse

  • linux_enterprise_server_for_sap
  • linux_enterprise_high_performance_computing
  • linux_enterprise_server

debian

  • debian_linux

artifex

  • ghostscript
CWE
CWE-824

Access of Uninitialized Pointer