Security Advisory
CVE-2013-5653
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.