Format string error in Ghostscript - CVE-2024-29510
Published: June 19, 2024 / Updated: July 19, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a format string error. A remote attacker can supply a specially crafted input that contains format string specifiers and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Debian Linux
Oracle Solaris
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libgs9 (Ubuntu package)
ghostscript (Ubuntu package)
libgs9-common (Ubuntu package)
ghostscript-doc (Ubuntu package)
ghostscript-x (Ubuntu package)
libgs-dev (Ubuntu package)
ghostscript-debugsource
ghostscript-devel
ghostscript-tools-dvipdf
ghostscript-help
ghostscript-debuginfo
ghostscript
ghostscript-x11-debuginfo
ghostscript-x11
ghostscript (Debian package)
ghostscript (Red Hat package)
ghostscript-tools-fonts
ghostscript-tools-printing
libgs
libgs-devel
ghostscript-doc
libgs10-common (Ubuntu package)
libgs10 (Ubuntu package)
libgs-common (Ubuntu package)
ghostscript-gtk
app-text/ghostscript-gpl
OpenShift API for Data Protection (OADP)
How to mitigate CVE-2024-29510
Oracle Solaris - update to 11.4 SRU 71
OpenShift API for Data Protection (OADP) - update to 1.3.4
libgs9 (Ubuntu package) - addressed in versions 9.50~dfsg-5ubuntu4.12, 9.55.0~dfsg1-0ubuntu5.7
ghostscript (Ubuntu package) - addressed in versions 9.50~dfsg-5ubuntu4.12, 9.55.0~dfsg1-0ubuntu5.7, 10.01.2~dfsg1-0ubuntu2.3, 10.02.1~dfsg1-0ubuntu7.1
libgs9-common (Ubuntu package) - addressed in versions 9.50~dfsg-5ubuntu4.12, 9.55.0~dfsg1-0ubuntu5.7, 10.01.2~dfsg1-0ubuntu2.3
ghostscript-doc (Ubuntu package) - addressed in versions 9.50~dfsg-5ubuntu4.12, 9.55.0~dfsg1-0ubuntu5.7, 10.01.2~dfsg1-0ubuntu2.3, 10.02.1~dfsg1-0ubuntu7.1
ghostscript-x (Ubuntu package) - addressed in versions 9.50~dfsg-5ubuntu4.12, 9.55.0~dfsg1-0ubuntu5.7, 10.01.2~dfsg1-0ubuntu2.3
libgs-dev (Ubuntu package) - addressed in versions 9.50~dfsg-5ubuntu4.12, 9.55.0~dfsg1-0ubuntu5.7, 10.01.2~dfsg1-0ubuntu2.3, 10.02.1~dfsg1-0ubuntu7.1
ghostscript-debugsource - addressed in versions 9.52-15, 9.55.0-10, 9.55.0-11
ghostscript-devel - addressed in versions 9.52-15, 9.55.0-10, 9.55.0-11
ghostscript-tools-dvipdf - addressed in versions 9.52-15, 9.55.0-10, 9.55.0-11
ghostscript-help - addressed in versions 9.52-15, 9.55.0-10, 9.55.0-11
ghostscript-debuginfo - addressed in versions 9.52-15, 9.55.0-10, 9.55.0-11
ghostscript - addressed in versions 9.52-15, 9.55.0-10, 9.55.0-11
ghostscript-x11-debuginfo - addressed in versions 9.52-23.80.1, 9.52-150000.194.1
ghostscript - addressed in versions 9.52-23.80.1, 9.52-150000.194.1
ghostscript-x11 - addressed in versions 9.52-23.80.1, 9.52-150000.194.1
ghostscript-devel - addressed in versions 9.52-23.80.1, 9.52-150000.194.1
ghostscript-debugsource - addressed in versions 9.52-23.80.1, 9.52-150000.194.1
ghostscript-debuginfo - addressed in versions 9.52-23.80.1, 9.52-150000.194.1
ghostscript (Debian package) - addressed in versions 9.53.3~dfsg-7+deb11u7, 10.0.0~dfsg-11+deb12u4
ghostscript (Red Hat package) - update to 9.54.0-12.el9_2.2
ghostscript - addressed in versions 9.54.0-17, 9.54.0-18, 10.02.1-2
ghostscript-tools-dvipdf - addressed in versions 9.54.0-17, 9.54.0-18, 10.02.1-2
ghostscript-tools-fonts - addressed in versions 9.54.0-17, 9.54.0-18, 10.02.1-2
ghostscript-tools-printing - addressed in versions 9.54.0-17, 9.54.0-18, 10.02.1-2
ghostscript-x11 - addressed in versions 9.54.0-17, 9.54.0-18, 10.02.1-2
libgs - addressed in versions 9.54.0-17, 9.54.0-18, 10.02.1-2
libgs-devel - addressed in versions 9.54.0-17, 9.54.0-18, 10.02.1-2
ghostscript-doc - addressed in versions 9.54.0-17, 9.54.0-18, 10.02.1-2
libgs10-common (Ubuntu package) - addressed in versions 10.01.2~dfsg1-0ubuntu2.3, 10.02.1~dfsg1-0ubuntu7.1
libgs10 (Ubuntu package) - addressed in versions 10.01.2~dfsg1-0ubuntu2.3, 10.02.1~dfsg1-0ubuntu7.1
libgs-common (Ubuntu package) - addressed in versions 10.01.2~dfsg1-0ubuntu2.3, 10.02.1~dfsg1-0ubuntu7.1
ghostscript-gtk - update to 10.02.1-2
ghostscript - addressed in versions 10.02.1-5.fc39, 10.02.1-10.fc40
app-text/ghostscript-gpl - update to 10.03.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in Artifex Ghostscript
- Ubuntu update for ghostscript
- Fedora 40 update for ghostscript
- Fedora 39 update for ghostscript
- SUSE update for ghostscript
- SUSE update for ghostscript
- Debian update for ghostscript
- Oracle Solaris update for thrid-party components
- Red Hat Enterprise Linux 9 update for ghostscript
- openEuler 20.03 LTS SP4 update for ghostscript
- openEuler 22.03 LTS SP3 update for ghostscript
- openEuler 22.03 LTS SP1 update for ghostscript
- Gentoo update for GPL Ghostscript
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Anolis OS update for ghostscript
- Anolis OS update for ghostscript
- Anolis OS update for ghostscript