An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-46956.json"
[
{
"digest": {
"line_hashes": [
"51349389685971879127722065848668744976",
"38793997789482228263181637852994441109",
"236140452785076161394171543611930980858",
"252281609283495551321526765862374920250"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "base/gscdefs.h"
},
"signature_type": "Line",
"id": "CVE-2024-46956-678ed2ab",
"source": "https://github.com/artifexsoftware/ghostpdl/commit/df8f4966577fff70320be2eb33cb55eb15d05d52",
"deprecated": false
}
]