CVE Vulnerabilities

CVE-2024-29508

Published: Jul 03, 2024 | Modified: Mar 17, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
4.4 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

Affected Software

NameVendorStart VersionEnd Version
GhostscriptArtifex*10.03.0 (excluding)
GhostscriptUbuntudevel*
GhostscriptUbuntuesm-infra/bionic*
GhostscriptUbuntuesm-infra/focal*
GhostscriptUbuntuesm-infra/xenial*
GhostscriptUbuntufocal*
GhostscriptUbuntujammy*
GhostscriptUbuntumantic*
GhostscriptUbuntunoble*
GhostscriptUbuntuoracular*
GhostscriptUbuntuplucky*
GhostscriptUbuntuupstream*

References