CVE Vulnerabilities

CVE-2024-29511

Active Debug Code

Published: Jul 03, 2024 | Modified: Jul 08, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.4 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.

Weakness

The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.

Affected Software

Name Vendor Start Version End Version
Ghostscript Ubuntu devel *
Ghostscript Ubuntu jammy *
Ghostscript Ubuntu mantic *
Ghostscript Ubuntu noble *
Ghostscript Ubuntu upstream *

Potential Mitigations

References