{"id":"CVE-2024-29508","details":"Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.","modified":"2026-03-14T14:56:34.874710Z","published":"2024-07-03T18:15:04.903Z","related":["SUSE-SU-2024:2547-1","SUSE-SU-2024:2627-1"],"references":[{"type":"WEB","url":"https://git.ghostscript.com/?p=ghostpdl.git%3Bh=ff1013a0ab485b66783b70145e342a82c670906a"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00022.html"},{"type":"ADVISORY","url":"https://www.openwall.com/lists/oss-security/2024/07/03/7"},{"type":"REPORT","url":"https://bugs.ghostscript.com/show_bug.cgi?id=707510"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29508.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"10.03.0"}]},{"events":[{"introduced":"0"},{"fixed":"10.03.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}