Description

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

INFO

Published Date :

2024-11-10T00:00:00.000Z

Last Modified :

2025-11-03T22:19:52.060Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-46953 vulnerability.

Vendors Products
Artifex
  • Ghostscript
Debian
  • Debian Linux
Redhat
  • Enterprise Linux
Suse
  • Linux Enterprise High Performance Computing
  • Linux Enterprise Server
  • Linux Enterprise Server For Sap

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact