CVE-2018-11645: Infoleak
Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which can allow remote attackers to determine the existence and size of arbitrary files.
Upstream bug:
https://bugs.ghostscript.com/showbug.cgi?id=697193
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=b60d50b7567369ad856cebe1efb6cd7dd2284219
Other sources
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
CVE-2018-11645
What is the title of the vulnerability?
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used…
What is the severity rating of CVE-2018-11645?
The severity rating of CVE-2018-11645 is medium, with a score of 5.3.
Which versions of Artifex Ghostscript are affected by CVE-2018-11645?
Artifex Ghostscript versions up to 9.20 are affected by CVE-2018-11645.
How can I fix CVE-2018-11645?
To fix CVE-2018-11645, update Artifex Ghostscript to version 9.21 or higher.