CVE-2013-5653Sensitive Information Exposure in Afpl Ghostscript

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 51.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 14

Description

The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianartifex/ghostscript< 9.19~dfsg-3.1+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-hh8r-vgv6-7j2f: The getenv and filenameforall functions in Ghostscript 92022-05-14
CVEList
CVE-2013-5653: The getenv and filenameforall functions in Ghostscript 92017-03-07
OSV
CVE-2013-5653: The getenv and filenameforall functions in Ghostscript 92017-03-07
OSV
ghostscript vulnerabilities2016-12-02

📋Vendor Advisories

3
Ubuntu
Ghostscript vulnerabilities2016-12-02
Red Hat
ghostscript: getenv and filenameforall ignore -dSAFER2013-10-21
Debian
CVE-2013-5653: ghostscript - The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER"...2013

💬Community

2
Bugzilla
CVE-2013-5653 ghostscript: getenv and filenameforall ignore -dSAFER [fedora-all]2016-11-01
Bugzilla
CVE-2013-5653 ghostscript: getenv and filenameforall ignore -dSAFER2016-09-29
CVE-2013-5653 — Sensitive Information Exposure | cvebase