Information disclosure in Ghostscript - CVE-2018-11645

 

Information disclosure in Ghostscript - CVE-2018-11645

Published: June 1, 2018 / Updated: June 5, 2018


Vulnerability identifier: #VU13177
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11645
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists in the psi/zfile.c code of Artifex Software Ghostscript due to improper security restrictions. A remote attacker can trick the victim into opening a specially crafted file that submits malicious input and access sensitive information, such as the existence and size of files. 


Affected software

Ghostscript
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing

How to mitigate CVE-2018-11645

Update to version 9.21.


External References

Related Security Bulletins