Arbitrary Code Execution Vulnerability in Artifex Ghostscript
CVE-2024-33871

Currently unrated

Key Information:

Vendor
Artifex
Vendor
CVE Published:
3 July 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.

News Articles

Multiple Flaws in Dell PowerProtect Allow System Compromise

Dell has released a Critical Security Update (DSA-2025-022) for its PowerProtect Data Domain (DD) systems to address multiple vulnerabilities.

References

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by GBHackers News

  • Vulnerability published

.