REDHAT-BUG-1380327: Medium severity ghostscript vulnerability
It was found that getenv and filenameforall ignore -dSAFER possibly allowing filesystem enumeration.
Upstream bug:
http://bugs.ghostscript.com/showbug.cgi?id=694724
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ab109aaeb3ddba59518b036fb288402a65cf7ce8
Reference: http://seclists.org/oss-sec/2016/q3/651
Reproducer:
%!PS (HOME) getenv { print (\n) print } { (variable not found\n) print } ifelse
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1380327?
REDHAT-BUG-1380327 is categorized as a critical vulnerability due to the potential for filesystem enumeration.
How do I fix REDHAT-BUG-1380327?
To mitigate REDHAT-BUG-1380327, it is recommended to apply the upstream patch available from the Ghostscript repository.
What software is affected by REDHAT-BUG-1380327?
The vulnerability REDHAT-BUG-1380327 affects Ghostscript software.
What are the potential risks of REDHAT-BUG-1380327?
Risks associated with REDHAT-BUG-1380327 include unauthorized access to filesystem information, which could lead to data leakage.
Is there a workaround for REDHAT-BUG-1380327?
A temporary workaround for REDHAT-BUG-1380327 may include disabling the affected functions until a patch is applied.