An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1504-1 | ghostscript security update |
Debian DSA |
DSA-4294-1 | ghostscript security update |
EUVD |
EUVD-2018-8602 | An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509. |
Ubuntu USN |
USN-3768-1 | Ghostscript vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:32:53.992Z
Reserved: 2018-09-10T00:00:00
Link: CVE-2018-16802
No data.
Status : Modified
Published: 2018-09-10T16:29:00.950
Modified: 2024-11-21T03:53:22.593
Link: CVE-2018-16802
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN