Path Traversal Vulnerability in Artifex Ghostscript Could Lead to Arbitrary File Access
CVE-2024-33870

Currently unrated

Key Information:

Vendor
Artifex
Vendor
CVE Published:
3 July 2024

Badges

📰 News Worthy

Summary

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.

News Articles

Fedora 40: ghostscript 2024-f433c5c4da Security Advisory Updates

Fedora Update Notification FEDORA-2024-f433c5c4da 2024-07-02 20:14:07.633450 Name: ghostscript Produ

References

Timeline

  • 📰

    First article discovered by Linux Security

  • Vulnerability published

.