CVE-2024-29510 is a format-string vulnerability in Artifex Ghostscript versions 9.50 through 10.03.0. The flaw is reachable through the uniprint output device when attacker-controlled device parameters, including upYMoveCommand with upOutputFormat set to /Pcl, are passed as a format string to gs_snprintf. Crafted format specifiers can disclose stack data and, with attacker-controlled data placed on the native stack, provide arbitrary memory read and write primitives. An exploit can clear Ghostscript's path_control_active field, disabling the default -dSAFER sandbox, and then use %pipe% to execute a shell command.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a vulnerable WordPress lab plus exploit material for two RCE chains: CVE-2024-2961 (glibc iconv/CNEXT PHP file-read to RCE) and CVE-2024-29510 (Ghostscript format-string to RCE). It is not just a standalone exploit; most of the repository builds a reproducible Docker environment that intentionally installs vulnerable components and exposes reachable web endpoints. Repository structure: the top level contains deployment/cleanup automation (setup.sh, clean.sh), two Docker Compose definitions for local and production-style labs, nginx configs, and a wordpress/ build context. The wordpress/ directory contains Dockerfiles that pin Ubuntu 22.04 with glibc 2.35, install WordPress, BuddyForms 2.7.6, PHP-FPM, and Ghostscript 10.02.1, plus entrypoint scripts that auto-configure the site. A custom mu-plugin adds an unauthenticated AJAX action convert_ps_to_image that accepts PS/EPS/PDF uploads, stores them under wp-content/uploads, and invokes ghostscript on them. Nginx is configured to expose uploads with autoindex enabled. Main exploit capabilities: the Python file exploit/cve=2024-2961.py is the primary exploit code. It adapts the public CNEXT technique to a WordPress AJAX endpoint by POSTing to /wp-admin/admin-ajax.php with action=upload_image_from_url. It uses a long php://filter iconv/base64 chain to turn a file-read primitive into disclosure of sensitive files such as /proc/self/maps and libc, then performs heap-oriented exploitation to execute an attacker-supplied command. This is a real exploit, not a detector. The included markdown exploit/cve-2024-29510.md is more of an operator note than code; it documents using a Metasploit Ghostscript module to generate a malicious PostScript file and then uploading it to the repository’s custom AJAX endpoint to obtain a reverse Meterpreter shell. Notable targeting details: the lab explicitly references WordPress, BuddyForms 2.7.6, glibc 2.35, and Ghostscript 10.02.1. The Docker setup intentionally enables risky conditions such as allow_url_fopen, PS/EPS/PDF processing, apparmor=unconfined, and extra Linux capabilities. Overall purpose: provide a realistic Ubuntu/WordPress environment for demonstrating how a web-exposed file-read primitive and a Ghostscript file-conversion feature can be chained into remote code execution.
This repository contains a single Metasploit module targeting CVE-2024-29510, a format string vulnerability in Ghostscript versions 10.03.0 and 10.01.2. The exploit allows an attacker to bypass the Ghostscript SAFER sandbox and execute arbitrary commands on the target system. The module generates a malicious Encapsulated PostScript (EPS) file, which, when processed by a vulnerable Ghostscript instance (directly or via a library such as ImageMagick), triggers the vulnerability and executes the attacker's payload. The default payload is a Meterpreter reverse shell, but any Metasploit command payload can be used. The module is weaponized, allowing for easy payload customization and integration into attack workflows. The main file is written in Ruby and follows the standard Metasploit module structure, with options for output filename and stack index adjustment. The exploit is file-format based, requiring the attacker to deliver the crafted EPS file to the target for processing.
This repository provides a proof-of-concept (POC) exploit for CVE-2024-29510, a format string vulnerability in Ghostscript 10.01.2. The exploit is based on research by Codean Labs and demonstrates both local and remote exploitation scenarios. The repository includes: - PostScript/EPS exploit files (document.eps, vulnapp/bad.eps) that leverage the format string vulnerability to disable Ghostscript's sandbox and execute arbitrary shell commands via the %pipe% operator. - A Bash stager script (run) that automates vulnerability checking and exploitation by downloading and executing the appropriate PostScript files. - Python and HTML files (vulnapp/app.py, vulnapp/templates/index.html) implementing a Flask-based web application (VulnApp) that allows users to upload PS/EPS files for conversion, simulating a remote attack surface. - Reverse shell payloads (index.html, vulnapp/shell.html) written in Python, which are fetched and executed on the victim to provide the attacker with a shell. - A Dockerfile for building a vulnerable environment with Ghostscript 10.02.1 (for demonstration) and the VulnApp web application. The exploit works by uploading a malicious EPS file to a vulnerable Ghostscript instance (locally or via the VulnApp web app). The EPS file manipulates internal Ghostscript structures to disable sandboxing, then uses %pipe% to execute a command that downloads and runs a Python reverse shell, connecting back to the attacker's host on port 443. The repository is well-structured for both local and remote testing, and provides all necessary components for demonstration and exploitation of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability included in the Alma Linux local security-check advisory. No technical flaw description or vulnerability-specific severity is provided.
A Ghostscript vulnerability described as a format string flaw that can lead to command execution/RCE, including abuse through file conversion services or embedded LibreOffice documents.
Unknown
A format string vulnerability in Ghostscript that could allow remote code execution via filesystem access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.