CVE-2018-16802
Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- artifex/ghostscript · debian/debian linux · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=3e5d316b72e3965b7968bb1d96baa137cd063ac6
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=643b24dbd002fb9c131313253c307cf3951b3d47
- https://access.redhat.com/errata/RHSA-2018:3834Third Party Advisory
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=5812b1b78fc4d36fdc293b7859de69241140d590
- https://lists.debian.org/debian-lts-announce/2018/09/msg00015.htmlMailing List, Third Party Advisory
- https://seclists.org/oss-sec/2018/q3/228Mailing List, Third Party Advisory
- https://seclists.org/oss-sec/2018/q3/229Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201811-12Third Party Advisory
- https://usn.ubuntu.com/3768-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4294Third Party Advisory
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=3e5d316b72e3965b7968bb1d96baa137cd063ac6
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=643b24dbd002fb9c131313253c307cf3951b3d47
- https://access.redhat.com/errata/RHSA-2018:3834Third Party Advisory
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=5812b1b78fc4d36fdc293b7859de69241140d590
- https://lists.debian.org/debian-lts-announce/2018/09/msg00015.htmlMailing List, Third Party Advisory
- https://seclists.org/oss-sec/2018/q3/228Mailing List, Third Party Advisory
- https://seclists.org/oss-sec/2018/q3/229Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201811-12Third Party Advisory
- https://usn.ubuntu.com/3768-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4294Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.