Your submission was sent successfully! Close

CVE-2018-16539

Published: 05 September 2018

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.

Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
ghostscript
Launchpad, Ubuntu, Debian
Upstream
Released (9.22~dfsg-3)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (9.22~dfsg+1-0ubuntu1.2)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (9.18~dfsg~0-0ubuntu2.9)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was released [9.10~dfsg-0ubuntu10.13])
Patches:
Upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=a054156d425b4dbdaaa9fda4b5f1182b27598c2b
Upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=150c8f69646b854a99f35f27edaae012eb2e900f