CVE-2024-29508: Artifex Ghostscript
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
Affected products
- Artifex Ghostscript: before 10.03.0 (fixed in 10.03.0)
Published 2024-07-03. Last modified 2026-06-17.