Heap-based buffer overflow in Ghostscript - CVE-2024-29509

 

Heap-based buffer overflow in Ghostscript - CVE-2024-29509

Published: July 5, 2024


Vulnerability identifier: #VU93812
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-29509
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to crash the application.

The vulnerability exists due to a boundary error when parsing passwords, when PDFPassword (e.g., for runpdf) has a 00 byte in the middle. A remote attacker can trick the victim to pass a specially crafted password to the application, trigger a heap-based buffer overflow and crash it.


Affected software

Ghostscript
Debian Linux
Ubuntu
openEuler
Fedora
ghostscript (Ubuntu package)
libgs9 (Ubuntu package)
ghostscript-help
ghostscript-tools-dvipdf
ghostscript-devel
ghostscript-debugsource
ghostscript-debuginfo
ghostscript
ghostscript (Debian package)
libgs10 (Ubuntu package)

How to mitigate CVE-2024-29509

Install updates from vendor's website.

Ghostscript - update to 10.03.0
ghostscript (Ubuntu package) - addressed in versions 9.50~dfsg-5ubuntu4.13, 9.55.0~dfsg1-0ubuntu5.9, 10.02.1~dfsg1-0ubuntu7.3
libgs9 (Ubuntu package) - addressed in versions 9.50~dfsg-5ubuntu4.13, 9.55.0~dfsg1-0ubuntu5.9
ghostscript-help - update to 9.55.0-23
ghostscript-tools-dvipdf - update to 9.55.0-23
ghostscript-devel - update to 9.55.0-23
ghostscript-debugsource - update to 9.55.0-23
ghostscript-debuginfo - update to 9.55.0-23
ghostscript - update to 9.55.0-23
ghostscript (Debian package) - update to 10.0.0~dfsg-11+deb12u5
libgs10 (Ubuntu package) - update to 10.02.1~dfsg1-0ubuntu7.3
ghostscript - addressed in versions 10.02.1-6.fc39, 10.02.1-7.fc39, 10.02.1-11.fc40, 10.02.1-12.fc40

External References

Related Security Bulletins