CVE-2018-16539

NameCVE-2018-16539
DescriptionIn Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1504-1, DSA-4288-1
NVD severitymedium (attack range: remote)
Debian Bugs907332

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ghostscript (PTS)jessie9.06~dfsg-2+deb8u7vulnerable
jessie (security)9.06~dfsg-2+deb8u11fixed
stretch9.20~dfsg-3.2+deb9u5fixed
stretch (security)9.25~dfsg-0+deb9u1fixed
buster, sid9.25~dfsg-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ghostscriptsource(unstable)9.22~dfsg-3medium907332
ghostscriptsourcejessie9.06~dfsg-2+deb8u8mediumDLA-1504-1
ghostscriptsourcestretch9.20~dfsg-3.2+deb9u4mediumDSA-4288-1

Notes

http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=a054156d425b4dbdaaa9fda4b5f1182b27598c2b
https://bugs.ghostscript.com/show_bug.cgi?id=699658
To not break cups with https://github.com/apple/cups/issues/5392
an additional (no-security) followup fix is needed as:
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=150c8f69646b854a99f35f27edaae012eb2e900f
Cf. https://bugs.debian.org/908300

Search for package or bug name: Reporting problems