ZeroHour

CVE-2016-7977

CVSS 3.0
5.5 medium
EPSS
5%p91
Published
()
Modified
Description

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

Vendors
artifex
Products
ghostscript
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.