CVE-2024-46955

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
Configurations

Configuration 1 (hide)

cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*

History

14 Nov 2024, 01:53

Type Values Removed Values Added
First Time Artifex
Suse linux Enterprise Server For Sap
Debian debian Linux
Debian
Suse linux Enterprise Server
Suse
Artifex ghostscript
Suse linux Enterprise High Performance Computing
CPE cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss:*:*:*
cpe:2.3:o:suse:linux_enterprise_server_for_sap:12:sp5:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:ltss_extended_security:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_high_performance_computing:12.0:sp5:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:-:*:*:*
References () https://bugs.ghostscript.com/show_bug.cgi?id=707990 - () https://bugs.ghostscript.com/show_bug.cgi?id=707990 - Permissions Required
References () https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=85bd9d2f4b792fe67aef22f1a4117457461b8ba6 - () https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=85bd9d2f4b792fe67aef22f1a4117457461b8ba6 - Patch
References () https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html - () https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html - Product
References () https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/ - () https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1/ - Third Party Advisory

12 Nov 2024, 20:35

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en psi/zcolor.c en Artifex Ghostscript anterior a la versión 10.04.0. Hay una lectura fuera de los límites al leer colores en el espacio de color indexado.

10 Nov 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-10 22:15

Updated : 2024-11-14 01:53


NVD link : CVE-2024-46955

Mitre link : CVE-2024-46955

CVE.ORG link : CVE-2024-46955


JSON object : View

Products Affected

debian

  • debian_linux

suse

  • linux_enterprise_server_for_sap
  • linux_enterprise_server
  • linux_enterprise_high_performance_computing

artifex

  • ghostscript
CWE
CWE-125

Out-of-bounds Read