CVE-2018-17961
published 2018-10-15CVE-2018-17961: Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue…
high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EXPLOIT
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 9.25 | 9.25 |
| artifex | ghostscript | >= 0 < 9.25~dfsg-3 | 9.25~dfsg-3 |
| artifex | ghostscript | >= 0 < 9.25~dfsg-3 | 9.25~dfsg-3 |
| artifex | ghostscript | >= 0 < 9.25~dfsg-3 | 9.25~dfsg-3 |
| artifex | ghostscript | >= 0 < 9.25~dfsg-3 | 9.25~dfsg-3 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 9.25~dfsg-3 (bookworm) | ghostscript 9.25~dfsg-3 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv7.8HIGH