Lucene search

K
redhatcveRedhat.comRH:CVE-2024-29508
HistoryJul 03, 2024 - 10:21 p.m.

CVE-2024-29508

2024-07-0322:21:16
redhat.com
access.redhat.com
11
artifex ghostscript
heap-based pointer disclosure
pdf_base_font_alloc

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

5.5

Confidence

Low

EPSS

0.001

Percentile

21.8%

A flaw was found in Ghostscript. Thepdf_base_font_alloc function used by the pdfwrite device will use a hexadecimal pointer representation for the constructed BaseFont name if the input name is empty. This flaw allows an attacker to obtain this pointer value by reading back to the output file after writing to a temporary writable and readable location.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

5.5

Confidence

Low

EPSS

0.001

Percentile

21.8%