CVE-2018-11645
01.06.2018, 12:29
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| artifex | ghostscript | 𝑥 ≤ 9.20 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| ghostscript |
| ||
| ghostscript-cups |
| ||
| ghostscript-debuginfo |
| ||
| ghostscript-devel |
| ||
| ghostscript-doc |
| ||
| ghostscript-gtk |
|
Common Weakness Enumeration
References