CVE-2018-16539
5.5
MEDIUM
CVSS 3.1
EPSS 0.35%
Description
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
How to fix CVE-2018-16539
To remediate CVE-2018-16539, upgrade the affected package to a fixed version below.
- Debian/ghostscript—upgrade to 9.22~dfsg-3 or later
Is CVE-2018-16539 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 9.22~dfsg-3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |