Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-11645

Опубликовано: 01 июн. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
Версия до 9.20 (включая)

EPSS

Процентиль: 67%
0.00538
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

CVSS3: 5.3
redhat
больше 9 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

CVSS3: 5.3
debian
больше 7 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status c ...

CVSS3: 5.3
github
больше 3 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

oracle-oval
больше 6 лет назад

ELSA-2019-2281: ghostscript security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 67%
0.00538
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200