Lucene search

K
redhatcveRedhat.comRH:CVE-2024-29511
HistoryJul 04, 2024 - 2:19 a.m.

CVE-2024-29511

2024-07-0402:19:29
redhat.com
access.redhat.com
5
artifex ghostscript
directory traversal
ocr

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0

Percentile

15.8%

A vulnerability was found in Ghostscript. When Tesseract is used for Optical Character Recognition (OCR), a directory traversal issue allows arbitrary file reading and writing of error messages to arbitrary files via the OCRLanguage. This issue causes an arbitrary file read/write through the Tesseract configuration.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0

Percentile

15.8%