Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7977

Опубликовано: 28 сент. 2016
Источник: redhat
CVSS3: 6.2
CVSS2: 4.3
EPSS Низкий

Описание

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

It was found that ghostscript function .libfile did not honor the -dSAFER option, usually used when processing untrusted documents, leading to information disclosure. A specially crafted postscript document could, in the context of the gs process, retrieve file content on the target machine.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ghostscriptWill not fix
Red Hat OpenShift Enterprise 2ghostscriptWill not fix
Red Hat Enterprise Linux 6ghostscriptFixedRHSA-2017:001404.01.2017
Red Hat Enterprise Linux 7ghostscriptFixedRHSA-2017:001304.01.2017

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1380415ghostscript: .libfile does not honor -dSAFER

EPSS

Процентиль: 77%
0.01067
Низкий

6.2 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

CVSS3: 5.5
nvd
больше 8 лет назад

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

CVSS3: 5.5
debian
больше 8 лет назад

Ghostscript before 9.21 might allow remote attackers to bypass the SAF ...

CVSS3: 5.5
github
больше 3 лет назад

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

suse-cvrf
около 9 лет назад

Security update for ghostscript-library

EPSS

Процентиль: 77%
0.01067
Низкий

6.2 Medium

CVSS3

4.3 Medium

CVSS2

Уязвимость CVE-2016-7977