Описание
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 10.02.1~dfsg1-0ubuntu9 |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | released | 9.50~dfsg-5ubuntu4.12 |
| esm-infra/xenial | not-affected | code not present |
| focal | released | 9.50~dfsg-5ubuntu4.12 |
| jammy | released | 9.55.0~dfsg1-0ubuntu5.7 |
| mantic | released | 10.01.2~dfsg1-0ubuntu2.3 |
| noble | released | 10.02.1~dfsg1-0ubuntu7.1 |
| oracular | released | 10.02.1~dfsg1-0ubuntu9 |
| plucky | released | 10.02.1~dfsg1-0ubuntu9 |
Показывать по
EPSS
6.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
An issue was discovered in Artifex Ghostscript before 10.03.1. There i ...
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
Уязвимость интерпретатора набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, связанная с ошибками в обработке относительного пути к каталогу, позволяющая нарушителю выполнить произвольный код
EPSS
6.3 Medium
CVSS3