#VU92102 Insecure DLL loading in Ghostscript - CVE-2024-33871
Published: June 13, 2024
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the "Driver" parameter for the "opvp"/"oprp" device specifies the name of a dynamic library and allows any library to be loaded. A remote attacker can pass a specially crafted document to the application and execute arbitrary library on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.