[HN Gopher] CVE-2024-29510 - Exploiting Ghostscript using format...
___________________________________________________________________
CVE-2024-29510 - Exploiting Ghostscript using format strings
Author : ThomasRinsma
Score : 30 points
Date : 2024-07-02 14:31 UTC (8 hours ago)
(HTM) web link (codeanlabs.com)
(TXT) w3m dump (codeanlabs.com)
| mistrial9 wrote:
| for v10.03 or less from the article.. patched in Debian systems
| last May ?
|
| https://tracker.debian.org/pkg/ghostscript
| pryelluw wrote:
| Friendly question given the fatigue around bs critical CVEs. Is
| this properly rated?
| pvg wrote:
| The article describes the vulnerability in some detail so you
| don't have to rely on the rating at all. In fact, you can
| completely ignore any mention of CVEs lose nothing.
| nieve wrote:
| It allows full RCE from an uploaded or opened file. That seems
| reasonably critical to me.
| out_of_protocol wrote:
| Does this work with .pdf files? i.e. attacker uploads
| evil.pdf
| SkyPuncher wrote:
| If I see a vulnerability in Ghostscript, I basically assume is
| full RCE at this point..
___________________________________________________________________
(page generated 2024-07-02 23:01 UTC)