CVE-2024-46956

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 10, 2024
Updated: Nov 14, 2024
CWE ID 125

Summary

CVE-2024-46956 is a newly discovered vulnerability affecting Artifex Ghostscript before version 10.04.0. This issue lies in the filenameforall function of psi/zfile.c. An out-of-bounds data access flaw exists in this component that enables attackers to execute arbitrary code. By manipulating filenames, adversaries can exploit this vulnerability and gain unauthorized access to systems running vulnerable versions of Ghostscript. This weakness poses a significant risk, and it is strongly recommended that users update to the latest version of Ghostscript to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share