CVE-2024-29508: Artifex Ghostscript

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

Affected products

  • Artifex Ghostscript: before 10.03.0 (fixed in 10.03.0)

Published 2024-07-03. Last modified 2026-06-17.