CVE-2018-15908: High severity ghostscript vulnerability
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
Other sources
It was discovered that the ghostscript .tempfile function did not properly handle file permissions. A specially crafted PostScript document could possibly exploit this to bypass the -dSAFER protection and delete files or disclose their content.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Artifex Ghostscript vulnerability?
The vulnerability ID for this Artifex Ghostscript vulnerability is CVE-2018-15908.
What is the severity of CVE-2018-15908?
The severity of CVE-2018-15908 is high, with a severity value of 7.8.
Which software versions are affected by CVE-2018-15908?
Artifex Ghostscript 9.23 is affected by CVE-2018-15908.
How can attackers exploit CVE-2018-15908?
Attackers can exploit CVE-2018-15908 by supplying malicious PostScript files to bypass .tempfile restrictions and write files.
Are there any references for CVE-2018-15908?
Yes, you can find references for CVE-2018-15908 at the following links: [Link 1](http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=0d3901189f245232f0161addf215d7268c4d05a3), [Link 2](https://www.kb.cert.org/vuls/id/332928), [Link 3](https://www.debian.org/security/2018/dsa-4288).