yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-46956
Component Overview
Vulnerability Overview
Name
CVE-2024-46956
Source
NVD (
link
)
Debian (
link
)
Description
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
CWEs
CWE-125
CWE-125
Published Date
Nov 10, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.ghostscript.com/show_bug.cgi?id=707895
Permissions Required
https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca
Patch
https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html
Product
https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/
Third Party Advisory
Analysis
#
Affected Component
Analysis
ghostscript
Patched
Vulnerability Ratings
#
7.8
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ghostscript
buildroot
2025.02.x
10.07.0
Not Affected
ghostscript
buildroot
master
10.07.0
Not Affected
ghostscript
yocto
master
10.07.1
Not Affected
ghostscript
yocto
scarthgap
10.05.1
Not Affected
Resolved with patches
#
ghostscript (yocto:kirkstone)
#
Title
Author
Resolve
1
PostScript interpreter - fix buffer length check
Zdenek Hutyra <zhutyra@centrum.cz>
CVE-2024-46956