Wind River Support Network

HomeDefectsLIN1022-8107
Fixed

LIN1022-8107 : Security Advisory - ghostscript - CVE-2024-33870

Created: May 9, 2024    Updated: Nov 7, 2024
Resolved Date: Oct 8, 2024
Found In Version: 10.22.33.1
Fix Version: 10.22.33.19
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.

https://nvd.nist.gov/vuln/detail/CVE-2024-33870

CVEs


Live chat
Online