CVE-2018-10194Improper Restriction of Operations within the Bounds of a Memory Buffer in Ghostscript

Severity
7.8HIGHNVD
EPSS
0.6%
top 29.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateMay 14

Description

The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

Debianartifex/ghostscript< 9.22~dfsg-2.1+3
Ubuntuartifex/ghostscript< 9.10~dfsg-0ubuntu10.12+2

Also affects: Debian Linux 7.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04, Enterprise Linux 7.7, 7.5

🔴Vulnerability Details

4
GHSA
GHSA-x8vv-69hx-8rmh: The set_text_distance function in devices/vector/gdevpdts2022-05-14
OSV
ghostscript vulnerabilities2018-04-30
CVEList
CVE-2018-10194: The set_text_distance function in devices/vector/gdevpdts2018-04-18
OSV
CVE-2018-10194: The set_text_distance function in devices/vector/gdevpdts2018-04-18

📋Vendor Advisories

3
Ubuntu
Ghostscript vulnerabilities2018-04-30
Red Hat
ghostscript: Stack-based out-of-bounds write in pdf_set_text_matrix function in gdevpdts.c2018-04-20
Debian
CVE-2018-10194: ghostscript - The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite comp...2018

💬Community

2
Bugzilla
CVE-2018-10194 ghostscript: Stack-based out-of-bounds write in pdf_set_text_matrix function in gdevpdts.c [fedora-all]2018-04-20
Bugzilla
CVE-2018-10194 ghostscript: Stack-based out-of-bounds write in pdf_set_text_matrix function in gdevpdts.c2018-04-18
CVE-2018-10194 — Artifex Ghostscript vulnerability | cvebase