2024年7月9日星期二

Ghostscript Remote Code Execution Vulnerability

Release Date: 8 Jul 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

A vulnerability was identified in Ghostscript. A remote attacker could exploit this vulnerability to trigger security restriction bypass and remote code execution on the targeted system.

 

Note:

Proof of concept exploit for CVE-2024-29510 exists on the internet.

To exploit the vulnerability, attackers require user interaction on the vulnerable system. Hence, the risk level is rated as Medium Risk.


Impact

  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  •  Versions piror to Ghostscript 10.03.1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendors have issued fixes. (Ghostscript 10.03.1)

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Juniper Junos OS 多個漏洞

Juniper Junos OS 多個漏洞 發佈日期: 2025年07月11日 風險: 中度風險 類型: 操作系統 - Network 於 Ju...