Lucene search

K
osvGoogleOSV:CVE-2024-33869
HistoryJul 03, 2024 - 7:15 p.m.

CVE-2024-33869

2024-07-0319:15:03
Google
osv.dev
7
artifex ghostscript
path traversal
command execution
postscript document

AI Score

6.8

Confidence

Low

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/…/%pipe%command# output filename.