Bugzilla – Bug 1227380
VUL-0: CVE-2024-29508: ghostscript: heap pointer leak in pdf_base_font_alloc()
Last modified: 2024-07-17 20:30:01 UTC
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc. References: https://bugs.ghostscript.com/show_bug.cgi?id=707510 http://www.openwall.com/lists/oss-security/2024/07/03/7 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-29508 https://www.cve.org/CVERecord?id=CVE-2024-29508 https://git.ghostscript.com/?p=ghostpdl.git;h=ff1013a0ab485b66783b70145e342a82c670906a https://bugs.ghostscript.com/show_bug.cgi?id=707662 https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/ https://bugzilla.redhat.com/show_bug.cgi?id=2295627
SUSE-SU-2024:2547-1: An update that solves one vulnerability can now be installed. Category: security (moderate) Bug References: 1227380 CVE References: CVE-2024-29508 Maintenance Incident: [SUSE:Maintenance:34800](https://smelt.suse.de/incident/34800/) Sources used: SUSE Linux Enterprise Software Development Kit 12 SP5 (src): ghostscript-9.52-23.83.1 SUSE Linux Enterprise High Performance Computing 12 SP5 (src): ghostscript-9.52-23.83.1 SUSE Linux Enterprise Server 12 SP5 (src): ghostscript-9.52-23.83.1 SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): ghostscript-9.52-23.83.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.