CVE-2024-29510 – Exploiting Ghostscript using format strings
1–10 of 10 posts
Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#2for v10.03 or less from the article.. patched in Debian systems last May ?
Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#3Friendly question given the fatigue around bs critical CVEs. Is this properly rated?
Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#4Friendly question given the fatigue around bs critical CVEs. Is this properly rated?
The article describes the vulnerability in some detail so you don't have to rely on the rating at all. In fact, you can completely ignore any mention of CVEs lose nothing.
Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#5Friendly question given the fatigue around bs critical CVEs. Is this properly rated?
It allows full RCE from an uploaded or opened file. That seems reasonably critical to me.
Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#6Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#7Friendly question given the fatigue around bs critical CVEs. Is this properly rated?
If I see a vulnerability in Ghostscript, I basically assume is full RCE at this point..
Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#8%n strikes again.
I believe that by default on osx %n is only respected if the format string is in readonly memory, I thought the default in Linux was to just ignore it?
Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#9Re: CVE-2024-29510 – Exploiting Ghostscript using format strings
#10Friendly question given the fatigue around bs critical CVEs. Is this properly rated?
It allows full RCE from an uploaded or opened file. That seems reasonably critical to me.
Thats.. in bad faith.
If thats the qualification for "remote" then you can say that every attack is remote and it clearly isnt.