Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6hc-9c6c-f599

Опубликовано: 03 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.

EPSS

Процентиль: 6%
0.00028
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
ubuntu
12 месяцев назад

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.

CVSS3: 5.3
redhat
около 1 года назад

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.

CVSS3: 5.3
nvd
12 месяцев назад

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.

CVSS3: 5.3
debian
12 месяцев назад

An issue was discovered in Artifex Ghostscript before 10.03.1. Path tr ...

CVSS3: 8.8
fstec
12 месяцев назад

Уязвимость файла base/gpmisc.c набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, связанная с неправильной проверкой входных данных, позволяющая нарушителю выполнить произвольный код в системе

EPSS

Процентиль: 6%
0.00028
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22