An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-03T00:00:00
Updated: 2024-08-02T02:42:59.809Z
Reserved: 2024-04-27T00:00:00
Link: CVE-2024-33871
Vulnrichment
Updated: 2024-08-02T02:42:59.809Z
NVD
Status : Awaiting Analysis
Published: 2024-07-03T19:15:03.943
Modified: 2024-11-21T09:17:38.523
Link: CVE-2024-33871
Redhat