cve/2024/CVE-2024-29511.md
2024-07-25 21:25:12 +00:00

771 B

CVE-2024-29511

Description

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.

POC

Reference

Github

No PoCs found on GitHub currently.