CVE-2024-29507
Publication date 3 July 2024
Last updated 24 July 2024
Ubuntu priority
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
Status
Package | Ubuntu Release | Status |
---|---|---|
ghostscript | 24.04 LTS noble |
Fixed 10.02.1~dfsg1-0ubuntu7.3
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
Notes
mdeslaur
per Debian, introduced by: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=316c3a08269212f1005709da64efcb383f8f5ce0 looks like this also introduced it: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=9ebc7de2f18bb8b899f9298bdbc6b1a8fb66c6b5
References
Related Ubuntu Security Notices (USN)
- USN-6897-1
- Ghostscript vulnerabilities
- 15 July 2024