An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-46953.json"
[
{
"signature_type": "Line",
"id": "CVE-2024-46953-678ed2ab",
"target": {
"file": "base/gscdefs.h"
},
"digest": {
"line_hashes": [
"51349389685971879127722065848668744976",
"38793997789482228263181637852994441109",
"236140452785076161394171543611930980858",
"252281609283495551321526765862374920250"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/artifexsoftware/ghostpdl/commit/df8f4966577fff70320be2eb33cb55eb15d05d52"
}
]