⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.
Severity
7.8HIGHNVD
EPSS
91.8%
top 0.31%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 5
Latest updateMay 13

Description

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

Debianartifex/ghostscript< 9.25~dfsg-1+3
CVEListV5artifex/ghostscript9.07

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, Enterprise Linux 7.5

🔴Vulnerability Details

4
GHSA
GHSA-98rm-3v6h-p8j6: An issue was discovered in Artifex Ghostscript before 92022-05-13
OSV
CVE-2018-16509: An issue was discovered in Artifex Ghostscript before 92018-09-05
CVEList
CVE-2018-16509: An issue was discovered in Artifex Ghostscript before 92018-09-05
VulnCheck
Artifex Ghostscript Restoration of Privilege Vulnerability2018

💥Exploits & PoCs

1
Exploit-DB
Ghostscript - Failed Restore Command Execution (Metasploit)2018-09-10

📋Vendor Advisories

19
Red Hat
ghostscript: Safer mode bypass by .forceput exposure in setsystemparams (701443)2019-08-28
Red Hat
ghostscript: Safer mode bypass by .forceput exposure in setuserparams (701444)2019-08-28
Red Hat
ghostscript: -dSAFER escape via .buildfont1 (701394)2019-08-12
Red Hat
ghostscript: superexec operator is available (700585)2019-03-21
Red Hat
ghostscript: forceput in DefineResource is still accessible (700576)2019-03-21

💬Community

13
Bugzilla
CVE-2019-10216 ghostscript: -dSAFER escape via .buildfont1 (701394)2019-08-02
Bugzilla
CVE-2019-3838 ghostscript: forceput in DefineResource is still accessible (700576)2019-02-15
Bugzilla
CVE-2019-3835 ghostscript: superexec operator is available (700585)2019-02-15
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-61162019-02-07
Bugzilla
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)2019-01-16
CVE-2018-16509 — Incomplete List of Disallowed Inputs | cvebase