CVE-2024-46953
7.8
HIGH
CVSS 3.1
EPSS 0.11%
Description
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
How to fix CVE-2024-46953
To remediate CVE-2024-46953, upgrade the affected package to a fixed version below.
- Alpine/ghostscript—upgrade to 10.04.0-r0 or later
- —upgrade to 9.53.3~dfsg-7+deb11u9 or later
Is CVE-2024-46953 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 10.04.0-r0
- from 0, < 9.53.3~dfsg-7+deb11u9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |