An issue was discovered in Artifex Ghostscript before 10...
Moderate severity
Unreviewed
Published
Jul 3, 2024
to the GitHub Advisory Database
•
Updated Nov 8, 2024
Description
Published by the National Vulnerability Database
Jul 3, 2024
Published to the GitHub Advisory Database
Jul 3, 2024
Last updated
Nov 8, 2024
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
References