CVE-2017-15652

MEDIUM

Artifex Ghostscript 9.22 - Exposure of Sensitive Information

Title source: llm
STIX 2.1

Description

Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of imagemagick also use libga, so it was affected as well.

References (3)

Core 3
Core References
Exploit, Patch, Vendor Advisory x_refsource_misc
https://bugs.ghostscript.com/show_bug.cgi?id=698676
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108463

Scores

CVSS v3 5.5
EPSS 0.0026
EPSS Percentile 48.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
artifex/ghostscript 9.22
Published May 23, 2019
Tracked Since Feb 18, 2026