CVE-2024-29506
Ghostscript vulnerability analysis and mitigation

Overview

Artifex Ghostscript before version 10.03.0 contains a stack-based buffer overflow vulnerability in the pdfiapplyfilter() function. The vulnerability can be triggered via a long PDF filter name when the PDFDEBUG flag is enabled (NVD, OSS Security).

Technical details

The vulnerability exists in the pdfiapplyfilter() function where the PDFDEBUG flag controls the value of ctx->args.debug. When enabled, it performs a memcpy operation into a fixed-size stack buffer of 100 bytes without proper bounds checking. The input (n->data, representing the PDF filter name) is an attacker-controlled buffer of arbitrary size, and a filter name larger than 100 bytes will overflow the 'str' buffer (OSS Security). The vulnerability has been assigned a CVSS v3.1 Base Score of 8.8 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) (NVD).

Impact

The successful exploitation of this vulnerability could lead to stack buffer overflow, potentially resulting in arbitrary code execution with the privileges of the Ghostscript process. The high CVSS score indicates that successful exploitation could lead to a complete compromise of confidentiality, integrity, and availability of the target system (NVD).

Mitigation and workarounds

The vulnerability has been fixed in Ghostscript version 10.03.0. Users are advised to upgrade to this version or later. The fix was implemented through commit 77dc7f699beba606937b7ea23b50cf5974fa64b1 in the Ghostscript repository (Ghostscript Bug).

Additional resources


SourceThis report was generated using AI

Related Ghostscript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59800MEDIUM5.5
  • GhostscriptGhostscript
  • cpe:2.3:a:artifex:ghostscript
NoYesSep 22, 2025
CVE-2025-59799MEDIUM5.5
  • GhostscriptGhostscript
  • ghostscript-x11-debuginfo
NoYesSep 22, 2025
CVE-2025-59798MEDIUM5.5
  • GhostscriptGhostscript
  • libgs-devel
NoYesSep 22, 2025
CVE-2025-7462MEDIUM5.3
  • GhostscriptGhostscript
  • ghostscript-gtk-debuginfo
NoYesJul 12, 2025
CVE-2025-59801MEDIUM4.3
  • GhostscriptGhostscript
  • ghostscript
NoYesSep 22, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management