Red Hat Security Advisory 2017-0013-01

Discussion in 'News Aggregator' started by Packet Storm, 5 Jan 2017.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2017-0013-01 - The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed. Security Fix: It was found that the ghostscript functions getenv, filenameforall and .libfile did not honor the -dSAFER option, usually used when processing untrusted documents, leading to information disclosure. A specially crafted postscript document could read environment variable, list directory and retrieve file content respectively, from the target.

    Continue reading...
     

Share This Page

Loading...