An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
| Software | From | Fixed in |
|---|---|---|
| artifex / ghostscript | - | 10.04.0 |
| debian / debian_linux | 12.0 | 12.0.x |
| suse / linux_enterprise_high_performance_computing | 12.0-sp5 | 12.0-sp5.x |
| suse / linux_enterprise_server | 12-sp5 | 12-sp5.x |
| suse / linux_enterprise_server_for_sap | 12-sp5 | 12-sp5.x |