Remote Code Execution Vulnerability in Ghostscript 9.10

Remote Code Execution Vulnerability in Ghostscript 9.10

CVE-2013-5653 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.

Learn more about our Web Application Penetration Testing UK.