yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-29508
Component Overview
Vulnerability Overview
Name
CVE-2024-29508
Source
NVD (
link
)
Debian (
link
)
Description
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
CWEs
CWE-122
Published Date
Jul 3, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.ghostscript.com/show_bug.cgi?id=707510
Issue Tracking
https://git.ghostscript.com/?p=ghostpdl.git%3Bh=ff1013a0ab485b66783b70145e342a82c670906a
Broken Link
https://www.openwall.com/lists/oss-security/2024/07/03/7
Mailing List
https://bugs.ghostscript.com/show_bug.cgi?id=707510
Issue Tracking
https://git.ghostscript.com/?p=ghostpdl.git%3Bh=ff1013a0ab485b66783b70145e342a82c670906a
Broken Link
https://www.openwall.com/lists/oss-security/2024/07/03/7
Mailing List
Analysis
#
Affected Component
Analysis
ghostscript
Patched
Vulnerability Ratings
#
3.3
CVSSv31
3.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ghostscript
buildroot
2025.02.x
10.07.0
Not Affected
ghostscript
buildroot
master
10.07.0
Not Affected
ghostscript
yocto
master
10.07.1
Not Affected
ghostscript
yocto
scarthgap
10.05.1
Not Affected
Resolved with patches
#
ghostscript (yocto:kirkstone)
#
Title
Author
Resolve
1
Bug 707510 - review printing of pointers
Ken Sharp <Ken.Sharp@artifex.com>
CVE-2024-29508
2
Coverity IDs 414141 & 414145
Ken Sharp <Ken.Sharp@artifex.com>
CVE-2024-29508