⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.
CVE-2018-16509 — Incomplete List of Disallowed Inputs in Ghostscript
CWE-184 — Incomplete List of Disallowed InputsCWE-843 — Type ConfusionCWE-460 — Improper Cleanup on Thrown ExceptionCWE-648 — Incorrect Use of Privileged APIsCWE-391 — Unchecked Error ConditionCWE-20 — Improper Input ValidationCWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer39 documents10 sources
Severity
7.8HIGHNVD
EPSS
91.8%
top 0.31%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedSep 5
Latest updateMay 13
Description
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages7 packages
Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, Enterprise Linux 7.5
🔴Vulnerability Details
4💥Exploits & PoCs
1📋Vendor Advisories
19💬Community
13Bugzilla
▶
Bugzilla▶
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)↗2019-01-16