Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2024-33870
HistoryJul 03, 2024 - 12:00 a.m.

CVE-2024-33870

2024-07-0300:00:00
mitre
github.com
5
artifex ghostscript
path traversal
arbitrary files
postscript document

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of …/…/foo to ./…/…/foo and this will grant access if ./ is permitted.

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial