CVE-2018-16509
05.09.2018, 06:29
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| artifex | ghostscript | 𝑥 < 9.24 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| artifex | gpl_ghostscript | 𝑥 < 9.26 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ghostscript |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ghostscript-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ghostscript-x11 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libspectre-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libspectre1 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| ghostscript |
| ||||
| ghostscript-cups |
| ||||
| ghostscript-devel |
| ||||
| ghostscript-doc |
| ||||
| ghostscript-gtk |
|
References