CVE-2024-29511
HIGHDescription
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
Is your site exposed to CVE-2024-29511?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| artifex | ghostscript |
References
Other References
Frequently Asked Questions
What is CVE-2024-29511? +
How severe is CVE-2024-29511? +
What products are affected by CVE-2024-29511? +
How do I check if I'm vulnerable to CVE-2024-29511? +
Related Vulnerabilities
An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, …
An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and …
A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with …
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable …
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof …
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An …