CVE-2024-29510
MEDIUM 6.3EPSS 28.0%
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
- CVSS v3.1
- 6.3 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N - EPSS
- 27.97% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2024-07-03
- Updated
- 2024-08-19
Proof-of-concept exploits (3)
- https://www.vicarius.io/vsociety/posts/critical-vulnerability-in-ghostscript-cve-2024-295…
- https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitatio…
- swsmith2391/CVE-2024-295101★ · 2024-07-10