INFSA-2024:4000: Ghostscript security update

Information about definition

Identificator: INFSA-2024:4000

Type: security

Release date: 2024-08-23 19:31:34 UTC

Information about package

The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.

Vulnerabilities description

  • CVE-2024-33871

    An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.8 no information
Critical, important, moderate, low

Updated packages