CVE-2018-16863
published 2018-12-03CVE-2018-16863: It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER…
PriorityP339high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.25%
66.3th percentile
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | — | — |
| debian | ghostscript | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ghostscript: incomplete fix for CVE-2018-16509
vendor_redhat·2018-12-03·CVSS 7.8
CVE-2018-16863 [HIGH] CWE-184 ghostscript: incomplete fix for CVE-2018-16509
ghostscript: incomplete fix for CVE-2018-16509
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document.
Statement: This vulnerability affects only Red Hat Enterprise Linux version 7. Red Hat Enterprise Linux version 6 is not affected by this vulnerability b
Debian
CVE-2018-16863: ghostscript - It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker c...
vendor_debian·2018·CVSS 7.8
CVE-2018-16863 [HIGH] CVE-2018-16863: ghostscript - It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker c...
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-83g5-f7jm-c8fc: It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2018-16863 [HIGH] CWE-184 GHSA-83g5-f7jm-c8fc: It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.
No detection rules found.
No public exploits indexed.
http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=520bb0ea7519http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=5516c614dc33http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=78911a01b67dhttp://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=79cccf641486https://access.redhat.com/errata/RHSA-2018:3761https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16863http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=520bb0ea7519http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=5516c614dc33http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=78911a01b67dhttp://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=79cccf641486https://access.redhat.com/errata/RHSA-2018:3761https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16863
2018-12-03
Published