Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-33871


An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.


Published

2024-07-03T19:15:03.943

Last Modified

2025-04-16T19:14:28.743

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application artifex ghostscript < 10.03.1 Yes

References