CVE-2013-5653: Infoleak
It was found that getenv and filenameforall ignore -dSAFER possibly allowing filesystem enumeration.
Upstream bug:
http://bugs.ghostscript.com/showbug.cgi?id=694724
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ab109aaeb3ddba59518b036fb288402a65cf7ce8
Reference: http://seclists.org/oss-sec/2016/q3/651
Reproducer:
%!PS (HOME) getenv { print (\n) print } { (variable not found\n) print } ifelse
Other sources
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5653?
CVE-2013-5653 has a high severity rating due to its potential for filesystem enumeration.
Which versions of Ghostscript are affected by CVE-2013-5653?
CVE-2013-5653 affects Ghostscript version 9.10.
How do I fix CVE-2013-5653?
To fix CVE-2013-5653, you should upgrade to a version of Ghostscript that includes the relevant security patches.
What is the main issue with CVE-2013-5653?
The main issue with CVE-2013-5653 is that certain functions are ignoring security settings, allowing unauthorized filesystem access.
Which operating system is mentioned in relation to CVE-2013-5653?
The Debian GNU/Linux version 8.0 is mentioned as being affected by CVE-2013-5653.