Red Hat Bugzilla – Bug 1585914
CVE-2018-11645 ghostscript: status command permitted with -dSAFER in psi/zfile.c allowing attackers to identify the size and existence of files
Last modified: 2018-10-31 21:31:25 EDT
Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which can allow remote attackers to determine the existence and size of arbitrary files. Upstream bug: https://bugs.ghostscript.com/show_bug.cgi?id=697193 Upstream patch: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=b60d50b7567369ad856cebe1efb6cd7dd2284219