yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-46952
Component Overview
Vulnerability Overview
Name
CVE-2024-46952
Source
NVD (
link
)
Debian (
link
)
Description
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).
CWEs
CWE-120
CWE-120
Published Date
Nov 10, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.ghostscript.com/show_bug.cgi?id=708001
Permissions Required
https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=b1f0827c30f59a2dcbc8a39e42cace7a1de35f7f
Patch
https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html
Product
Analysis
#
Affected Component
Analysis
ghostscript
Patched
Vulnerability Ratings
#
7.8
CVSSv31
8.4
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ghostscript
buildroot
2025.02.x
10.07.0
Not Affected
ghostscript
buildroot
master
10.07.0
Not Affected
ghostscript
yocto
master
10.07.1
Not Affected
ghostscript
yocto
scarthgap
10.05.1
Not Affected
Resolved with patches
#
ghostscript (yocto:kirkstone)
#
Title
Author
Resolve
1
PDF interpreter - sanitise W array values in Xref streams
Ken Sharp <Ken.Sharp@artifex.com>
CVE-2024-46952