Описание
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 9.21~dfsg+1-0ubuntu3.1 |
| bionic | not-affected | |
| devel | not-affected | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [9.10~dfsg-0ubuntu10.13]] |
| esm-infra/bionic | not-affected | |
| esm-infra/xenial | released | 9.18~dfsg~0-0ubuntu2.9 |
| precise/esm | DNE | |
| trusty | released | 9.10~dfsg-0ubuntu10.13 |
| trusty/esm | DNE | trusty was released [9.10~dfsg-0ubuntu10.13] |
| upstream | released | 9.21~dfsg-1 |
Показывать по
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status c ...
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.
ELSA-2019-2281: ghostscript security, bug fix, and enhancement update (LOW)
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3