Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-46956


An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.


Published

2024-11-10T22:15:12.943

Last Modified

2024-11-14T20:39:54.757

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-125
  • Type: Secondary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application artifex ghostscript < 10.04.0 Yes
Operating System debian debian_linux 12.0 Yes
Operating System suse linux_enterprise_high_performance_computing 12.0 Yes
Operating System suse linux_enterprise_server 12 Yes
Operating System suse linux_enterprise_server 12 Yes
Operating System suse linux_enterprise_server 12 Yes
Operating System suse linux_enterprise_server_for_sap 12 Yes

References