Live data from Hacker News

CVE-2024-29510 – Exploiting Ghostscript using format strings

codeanlabs.com

1–10 of 10 posts

Re: CVE-2024-29510 – Exploiting Ghostscript using format strings

#4
post #3

Friendly question given the fatigue around bs critical CVEs. Is this properly rated?

The article describes the vulnerability in some detail so you don't have to rely on the rating at all. In fact, you can completely ignore any mention of CVEs lose nothing.

Re: CVE-2024-29510 – Exploiting Ghostscript using format strings

#6
post #5
post #3

Friendly question given the fatigue around bs critical CVEs. Is this properly rated?

It allows full RCE from an uploaded or opened file. That seems reasonably critical to me.

Does this work with .pdf files? i.e. attacker uploads evil.pdf

Re: CVE-2024-29510 – Exploiting Ghostscript using format strings

#9
post #5

Earlier quoted context omitted.

It allows full RCE from an uploaded or opened file. That seems reasonably critical to me.

Does this work with .pdf files? i.e. attacker uploads evil.pdf

yes, also with .eps files

Re: CVE-2024-29510 – Exploiting Ghostscript using format strings

#10
post #5
post #3

Friendly question given the fatigue around bs critical CVEs. Is this properly rated?

It allows full RCE from an uploaded or opened file. That seems reasonably critical to me.

Thats.. in bad faith.

If thats the qualification for "remote" then you can say that every attack is remote and it clearly isnt.