Information disclosure in Ghostscript - CVE-2018-11645
Published: June 1, 2018 / Updated: June 5, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the psi/zfile.c code of Artifex Software Ghostscript due to improper security restrictions. A remote attacker can trick the victim into opening a specially crafted file that submits malicious input and access sensitive information, such as the existence and size of files.
Affected software
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing