Skip to main content

Active Debug Code

CVE-2024-29511

Severity High
Score 7.5/10

Summary

Artifex Ghostscript versions prior to 10.03.0rc1_test, when "Tesseract" is used for OCR, has a Directory Traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via `OCRLanguage`. For example, exploitation can use `debug_file` `/tmp/out` and `user_patterns_file` `/etc/passwd`.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-489 - Active Debug Code

The application is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.

Advisory Timeline

  • Published