Experts warn: Don’t ignore Ghostscript bug Fix it to prevent breach

July 6, 2024
1 min read





TLDR:

  • A vulnerability in Ghostscript, CVE-2024-29510, could lead to major breaches
  • RCE on machines running Ghostscript after bypassing -dSAFER sandbox

Infosec experts are warning about a critical vulnerability in Ghostscript that could potentially lead to significant breaches. Tracked as CVE-2024-29510, the vulnerability was originally reported in March and mitigated in April. However, researchers have found a way to achieve remote code execution (RCE) on systems running Ghostscript by bypassing the -dSAFER sandbox.

This vulnerability is especially concerning as Ghostscript is widely used across web applications, offering functionalities such as document conversion and previews. The exploit could allow attackers to read and write files, as well as achieve RCE on affected systems.

While the severity of the vulnerability has been rated medium, experts are warning that it could have much more severe implications, especially in automated workflows processing untrusted files. Previous experiences with similar vulnerabilities in Ghostscript have led to critical breaches, underscoring the importance of accurate severity assessments and prompt patching.


Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and