Latest Ghostscript vulnerability haunts experts as the next big breach enabler
ID: fda9903a-2dce-5101-a90d-aa48364ecc3b
STIX ID: report--fda9903a-2dce-5101-a90d-aa48364ecc3b
Feed Name: The Register (Security)
Threat Score
**Executive summary:** CVE-2024-29510 is a Ghostscript format-string vulnerability allowing arbitrary file read/write and remote code execution by bypassing the -dSAFER sandbox; a public PoC (EPS) is available and some reports indicate exploitation attempts. Given Ghostscript's pervasive use in document conversion, preview, printing and OCR workflows, unpatched systems could be widely impacted despite differing CVSS ratings; Ghostscript 10.03.1 includes mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
