ISOMAN

CVE

CVE-2018-16539

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

References

  1. http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=a054156d425b4dbdaaa9fda4b5f1182b27598c2b
  2. https://access.redhat.com/errata/RHSA-2018:3650
  3. https://bugs.ghostscript.com/show_bug.cgi?id=699658
  4. https://lists.debian.org/debian-lts-announce/2018/09/msg00015.html
  5. https://security.gentoo.org/glsa/201811-12
  6. https://usn.ubuntu.com/3768-1/
  7. https://www.artifex.com/news/ghostscript-security-resolved/
  8. https://www.debian.org/security/2018/dsa-4288
  9. http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=a054156d425b4dbdaaa9fda4b5f1182b27598c2b
  10. https://access.redhat.com/errata/RHSA-2018:3650
  11. https://bugs.ghostscript.com/show_bug.cgi?id=699658
  12. https://lists.debian.org/debian-lts-announce/2018/09/msg00015.html
  13. https://security.gentoo.org/glsa/201811-12
  14. https://usn.ubuntu.com/3768-1/
  15. https://www.artifex.com/news/ghostscript-security-resolved/
  16. https://www.debian.org/security/2018/dsa-4288