Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11645

Опубликовано: 05 окт. 2016
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

Ghostscript did not honor the -dSAFER option when executing the "status" instruction, which can be used to retrieve information such as a file's existence and size. A specially crafted postscript document could use this flow to gain information on the targeted system's filesystem content.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ghostscriptWill not fix
Red Hat Enterprise Linux 6ghostscriptWill not fix
Red Hat Enterprise Linux 8ghostscriptNot affected
Red Hat Enterprise Linux 7ghostscriptFixedRHSA-2019:228106.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1585914ghostscript: status command permitted with -dSAFER in psi/zfile.c allowing attackers to identify the size and existence of files

EPSS

Процентиль: 67%
0.00538
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

CVSS3: 5.3
nvd
больше 7 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

CVSS3: 5.3
debian
больше 7 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status c ...

CVSS3: 5.3
github
больше 3 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

oracle-oval
больше 6 лет назад

ELSA-2019-2281: ghostscript security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 67%
0.00538
Низкий

5.3 Medium

CVSS3