#VU13177 Information disclosure in Ghostscript - CVE-2018-11645
Published: June 1, 2018 / Updated: June 5, 2018
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the psi/zfile.c code of Artifex Software Ghostscript due to improper security restrictions. A remote attacker can trick the victim into opening a specially crafted file that submits malicious input and access sensitive information, such as the existence and size of files.