Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade ghostscript | Jan 11, 2017 | Oct 11, 2016 |
| Centos_linux | — | Upgrade ghostscript-gtkUpgrade ghostscript-develUpgrade ghostscript-debuginfoUpgrade ghostscript-docUpgrade ghostscript-cupsUpgrade ghostscript | Jan 27, 2017 | Oct 11, 2016 |
| Debian | — | Upgrade ghostscript | Mar 31, 2017 | Oct 11, 2016 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Oct 30, 2017 | May 23, 2017 |
| Ghostscript | — | Upgrade to Ghostscript version 9.21 | Oct 10, 2018 | May 23, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Nov 30, 2017 | May 23, 2017 |
| Oracle Solaris | — | Upgrade print/filter/ghostscript to version 9.26-0.175.3.36.0.10.0 on Solaris 11.3Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | May 23, 2017 |
| Oracle_linux | — | Upgrade ghostscript-develUpgrade ghostscriptUpgrade ghostscript-gtkUpgrade ghostscript-docUpgrade ghostscript-cups | Jan 5, 2017 | Sep 28, 2016 |
| Redhat_linux | — | Upgrade ghostscript-cupsUpgrade ghostscript-gtkUpgrade ghostscript-debuginfoUpgrade ghostscript-develUpgrade ghostscriptNo solution existsUpgrade ghostscript-doc | Jan 5, 2017 | Oct 11, 2016 |
| Suse | — | Upgrade ghostscript-develUpgrade ghostscript-fonts-stdUpgrade ghostscript-ijs-develUpgrade ghostscript-libraryUpgrade ghostscript-omniUpgrade ghostscriptUpgrade ghostscript-fonts-rusUpgrade ghostscript-fonts-otherUpgrade ghostscript-x11Upgrade libgimpprint-develUpgrade libgimpprint | Nov 3, 2016 | Oct 11, 2016 |
| Ubuntu | — | Upgrade libgs9-commonUpgrade ghostscript-xUpgrade libgs9Upgrade ghostscript | Dec 2, 2016 | Oct 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub