Ghostscript is an interpreter for PostScript™ and Portable Document Format (PDF) files. Ghostscript consists of a PostScript interpreter layer, and a graphics library.
Security Fix(es):
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.(CVE-2024-33869)
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.(CVE-2024-33870)
{ "severity": "Low" }
{ "noarch": [ "ghostscript-help-9.52-16.oe2003sp4.noarch.rpm" ], "aarch64": [ "ghostscript-9.52-16.oe2003sp4.aarch64.rpm", "ghostscript-debuginfo-9.52-16.oe2003sp4.aarch64.rpm", "ghostscript-debugsource-9.52-16.oe2003sp4.aarch64.rpm", "ghostscript-devel-9.52-16.oe2003sp4.aarch64.rpm", "ghostscript-tools-dvipdf-9.52-16.oe2003sp4.aarch64.rpm" ], "x86_64": [ "ghostscript-9.52-16.oe2003sp4.x86_64.rpm", "ghostscript-debuginfo-9.52-16.oe2003sp4.x86_64.rpm", "ghostscript-debugsource-9.52-16.oe2003sp4.x86_64.rpm", "ghostscript-devel-9.52-16.oe2003sp4.x86_64.rpm", "ghostscript-tools-dvipdf-9.52-16.oe2003sp4.x86_64.rpm" ], "src": [ "ghostscript-9.52-16.oe2003sp4.src.rpm" ] }