Skip to main content

Ghostscript Remote Code Execution Vulnerability

Release Date: 8 Jul 2024 1756 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability was identified in Ghostscript. A remote attacker could exploit this vulnerability to trigger security restriction bypass and remote code execution on the targeted system.

 

Note:

Proof of concept exploit for CVE-2024-29510 exists on the internet.

To exploit the vulnerability, attackers require user interaction on the vulnerable system. Hence, the risk level is rated as Medium Risk.


Impact

  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  •  Versions piror to Ghostscript 10.03.1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendors have issued fixes. (Ghostscript 10.03.1)

Vulnerability Identifier


Source


Related Link