CVE-2024-46956
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-46956 is a newly discovered vulnerability affecting Artifex Ghostscript before version 10.04.0. This issue lies in the filenameforall function of psi/zfile.c. An out-of-bounds data access flaw exists in this component that enables attackers to execute arbitrary code. By manipulating filenames, adversaries can exploit this vulnerability and gain unauthorized access to systems running vulnerable versions of Ghostscript. This weakness poses a significant risk, and it is strongly recommended that users update to the latest version of Ghostscript to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GhostScript
Affected Vendors
- Artifex