Bugzilla – Bug 1227379
VUL-0: CVE-2024-29509: ghostscript: heap buffer overflow via the PDFPassword parameter
Last modified: 2024-07-16 08:12:54 UTC
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle. References: https://bugs.ghostscript.com/show_bug.cgi?id=707510 http://www.openwall.com/lists/oss-security/2024/07/03/7 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-29509 https://www.cve.org/CVERecord?id=CVE-2024-29509 https://git.ghostscript.com/?p=ghostpdl.git;h=917b3a71fb20748965254631199ad98210d6c2fb https://bugs.ghostscript.com/show_bug.cgi?id=707662 https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/ https://bugzilla.redhat.com/show_bug.cgi?id=2295628