ISOMAN

CVE

CVE-2018-19475

psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

Severity
HIGH
CVSS
7.8
Published
Modified

Linked Releases

References

  1. http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=3005fcb9bb160af199e761e03bc70a9f249a987e
  2. http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=aeea342904978c9fe17d85f4906a0f6fcce2d315
  3. http://www.securityfocus.com/bid/106154
  4. https://access.redhat.com/errata/RHBA-2019:0327
  5. https://access.redhat.com/errata/RHSA-2019:0229
  6. https://bugs.ghostscript.com/show_bug.cgi?id=700153
  7. https://lists.debian.org/debian-lts-announce/2018/11/msg00036.html
  8. https://semmle.com/news/semmle-discovers-severe-vulnerability-ghostscript-postscript-pdf
  9. https://usn.ubuntu.com/3831-1/
  10. https://www.debian.org/security/2018/dsa-4346
  11. https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26
  12. http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=3005fcb9bb160af199e761e03bc70a9f249a987e
  13. http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=aeea342904978c9fe17d85f4906a0f6fcce2d315
  14. http://www.securityfocus.com/bid/106154
  15. https://access.redhat.com/errata/RHBA-2019:0327
  16. https://access.redhat.com/errata/RHSA-2019:0229
  17. https://bugs.ghostscript.com/show_bug.cgi?id=700153
  18. https://lists.debian.org/debian-lts-announce/2018/11/msg00036.html
  19. https://semmle.com/news/semmle-discovers-severe-vulnerability-ghostscript-postscript-pdf
  20. https://usn.ubuntu.com/3831-1/