#VU93812 Heap-based buffer overflow in Ghostscript - CVE-2024-29509
Published: July 5, 2024
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to a boundary error when parsing passwords, when PDFPassword (e.g., for runpdf) has a 00 byte in the middle. A remote attacker can trick the victim to pass a specially crafted password to the application, trigger a heap-based buffer overflow and crash it.