Wind River Support Network

HomeDefectsLIN1024-867
Fixed

LIN1024-867 : Security Advisory - ghostscript - CVE-2024-33870

Created: May 9, 2024    Updated: Aug 28, 2024
Resolved Date: Jul 7, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.

https://nvd.nist.gov/vuln/detail/CVE-2024-33870

CVEs


Live chat
Online