Currently there are several known security issues in Ghostscript:
CVE-2024-29510
CVE-2024-29506
CVE-2024-29507
CVE-2024-29508
CVE-2024-29509
CVE-2024-29510, see https://nvd.nist.gov/vuln/detail/cve-2024-29510
CVE-2024-29511
not fixed in actual Versions of Ubuntu? gs is part of CUPS and therefore on almost every Ubuntu computer. This is a very attractive security target for malicious people!
See for example:
- https://stackoverflow.com/questions/52998331/imagemagick-security-policy-pdf-blocking-conversion
- https://www.kb.cert.org/vuls/id/332928/
- https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2023/2023-248889-1012.pdf?__blob=publicationFile&v=2
- https://tuxcare.com/blog/ghostscript-vulnerability-actively-exploited-in-attacks/
- https://securityaffairs.com/165449/hacking/ghostscript-vulnerability-cve-2024-29510.html
Unfortunately, I don't know much about computer security. But what I have read worries me and I am surprised that the existing version 10.03.1 has not yet been rolled out generally.