Wind River Support Network

HomeDefectsLIN1021-8696
Fixed

LIN1021-8696 : Security Advisory - ghostscript - CVE-2024-33869

Created: May 9, 2024    Updated: Jul 3, 2024
Resolved Date: Jul 3, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

ghostscript: when stripping a potential Current Working Dirctory specifier from a path, make certain it really is a CWD, and not simply large ebough to be a CWD.

https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=5ae2e320d69a7d0973011796bd388cd5befa1a43

https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f5336e5b4154f515ac83bc5b9eba94302e6618d4


CREATE(Triage):(User=admin) CVE-2024-33869 (https://nvd.nist.gov/vuln/detail/CVE-2024-33869)

CVEs


Live chat
Online