Path Traversal Vulnerability in Artifex Ghostscript Could Lead to Arbitrary File Access
CVE-2024-33870

6.3MEDIUM

Key Information:

Vendor

Artifex

Vendor
CVE Published:
3 July 2024

Badges

๐Ÿ“ฐ News Worthy

What is CVE-2024-33870?

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

News Articles

Fedora 40: ghostscript 2024-f433c5c4da Security Advisory Updates

Fedora Update Notification FEDORA-2024-f433c5c4da 2024-07-02 20:14:07.633450 Name: ghostscript Produ

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ“ฐ

    First article discovered by Linux Security

  • Vulnerability published

.