[HN Gopher] CVE-2024-29510 - Exploiting Ghostscript using format...
       ___________________________________________________________________
        
       CVE-2024-29510 - Exploiting Ghostscript using format strings
        
       Author : ThomasRinsma
       Score  : 30 points
       Date   : 2024-07-02 14:31 UTC (8 hours ago)
        
 (HTM) web link (codeanlabs.com)
 (TXT) w3m dump (codeanlabs.com)
        
       | mistrial9 wrote:
       | for v10.03 or less from the article.. patched in Debian systems
       | last May ?
       | 
       | https://tracker.debian.org/pkg/ghostscript
        
       | pryelluw wrote:
       | Friendly question given the fatigue around bs critical CVEs. Is
       | this properly rated?
        
         | pvg wrote:
         | The article describes the vulnerability in some detail so you
         | don't have to rely on the rating at all. In fact, you can
         | completely ignore any mention of CVEs lose nothing.
        
         | nieve wrote:
         | It allows full RCE from an uploaded or opened file. That seems
         | reasonably critical to me.
        
           | out_of_protocol wrote:
           | Does this work with .pdf files? i.e. attacker uploads
           | evil.pdf
        
         | SkyPuncher wrote:
         | If I see a vulnerability in Ghostscript, I basically assume is
         | full RCE at this point..
        
       ___________________________________________________________________
       (page generated 2024-07-02 23:01 UTC)