In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
https://www.debian.org/security/2018/dsa-4288
https://usn.ubuntu.com/3768-1/
https://security.gentoo.org/glsa/201811-12
https://lists.debian.org/debian-lts-announce/2018/09/msg00015.html
https://access.redhat.com/errata/RHSA-2018:3650
https://www.artifex.com/news/ghostscript-security-resolved/
https://bugs.ghostscript.com/show_bug.cgi?id=699658
http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=a054156d425b4dbdaaa9fda4b5f1182b27598c2b
Source: Mitre, NVD
Published: 2018-09-05
Updated: 2024-11-21
Base Score: 4.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 5.5
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS: 0.00298