Active Debug Code
CVE-2024-29511
Summary
Artifex Ghostscript versions prior to 10.03.0rc1_test, when "Tesseract" is used for OCR, has a Directory Traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via `OCRLanguage`. For example, exploitation can use `debug_file` `/tmp/out` and `user_patterns_file` `/etc/passwd`.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-489 - Active Debug Code
The application is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
References
Advisory Timeline
- Published