cbcvebase.
CVE-2018-19475
published 2018-11-23

CVE-2018-19475: psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked…

PriorityP350high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
9.55%
94.9th percentile
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

Affected

20 ranges
VendorProductVersion rangeFixed in
artifexghostscript< 9.269.26
artifexghostscript>= 0 < 9.26~dfsg-19.26~dfsg-1
artifexghostscript>= 0 < 9.26~dfsg-19.26~dfsg-1
artifexghostscript>= 0 < 9.26~dfsg-19.26~dfsg-1
artifexghostscript>= 0 < 9.26~dfsg-19.26~dfsg-1
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianghostscript< ghostscript 9.26~dfsg-1 (bookworm)ghostscript 9.26~dfsg-1 (bookworm)
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatopenshift_container_platform

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=3005fcb9bb160af199e761e03bc70a9f249a987e
urlhttp://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=aeea342904978c9fe17d85f4906a0f6fcce2d315
pathpsi/zdevice2.c
  • The vulnerable function is `restore_page_device` in `psi/zdevice2.c`; monitor for Ghostscript processing PS or PDF files that trigger this code path without stack-space validation.
  • Attack vector includes specially-crafted PS or PDF files; also triggers via file-manager thumbnail generation — monitor thumbnail/preview processes spawning Ghostscript.
  • ·Red Hat Enterprise Linux 6 will NOT receive a fix; systems running RHEL 6 with Ghostscript remain permanently vulnerable unless mitigated via the CVE-2018-16509 mitigation guidance.
  • ·Starting from RHEL 7.6, the thumbnailer is executed in a sandbox, reducing the thumbnail-generation attack surface on that platform.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.