Bugzilla – Bug 1227381
VUL-0: CVE-2024-29507: ghostscript: stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters
Last modified: 2024-07-16 08:10:43 UTC
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters. References: https://bugs.ghostscript.com/show_bug.cgi?id=707510 http://www.openwall.com/lists/oss-security/2024/07/03/7 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-29507 https://www.cve.org/CVERecord?id=CVE-2024-29507 https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=7745dbe24514 https://bugs.ghostscript.com/show_bug.cgi?id=707662 https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/ https://bugzilla.redhat.com/show_bug.cgi?id=2295647