Описание
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
It was discovered that the ghostscript .tempfile function did not properly handle file permissions. An attacker could possibly exploit this to exploit this to bypass the -dSAFER protection and delete files or disclose their content via a specially crafted PostScript document.
Меры по смягчению последствий
Please see https://bugzilla.redhat.com/show_bug.cgi?id=1619748#c3
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | ghostscript | Will not fix | ||
| Red Hat Enterprise Linux 6 | ghostscript | Will not fix | ||
| Red Hat Enterprise Linux 8 | ghostscript | Not affected | ||
| Red Hat OpenShift Container Platform 3.10 | mediawiki | Not affected | ||
| Red Hat OpenShift Container Platform 3.11 | mediawiki | Not affected | ||
| Red Hat OpenShift Container Platform 3.2 | mediawiki | Not affected | ||
| Red Hat OpenShift Container Platform 3.3 | mediawiki | Not affected | ||
| Red Hat OpenShift Container Platform 3.4 | mediawiki | Not affected | ||
| Red Hat OpenShift Container Platform 3.5 | mediawiki | Not affected | ||
| Red Hat OpenShift Container Platform 3.6 | mediawiki | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
Связанные уязвимости
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to s ...
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
Уязвимость компонента .tempfile набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю обойти защиту –dSAFER , удалить файлы или получить несанкционированный доступ к защищаемой информации
EPSS
7.3 High
CVSS3