Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ghostscript | Ubuntu | devel | * |
Ghostscript | Ubuntu | jammy | * |
Ghostscript | Ubuntu | mantic | * |
Ghostscript | Ubuntu | noble | * |
Ghostscript | Ubuntu | upstream | * |