ALPINE-CVE-2024-33870 PUBLISHED CVSS 6.300000190734863 MEDIUM

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.

Risk Scores

CVSS v3.1
6.300000190734863
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products

VendorProductVersions
Alpine:v3.22ghostscript0, 9.56.1-r0, 9.55.0-r0
Alpine:v3.20ghostscript9.18-r0, 10.0.0-r0, 10.0.0-r1
Alpine:v3.18ghostscript0, 10.0.0-r2, 10.01.2-r0
Alpine:v3.21ghostscript9.21-r0, 9.20-r1, 8.71-r0
Alpine:v3.19ghostscript9.26-r2, 0, 10.0.0-r0
Alpine:v3.23ghostscript0, 10.0.0-r0, 10.0.0-r1

Timeline

References

Open in Interactive Console →