ZeroHour

CVE-2018-16509

PoC ×2
CVSS 3.0
7.8 high
EPSS
92%p100
Published
()
Modified
Description

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

Vendors
debianartifexcanonicalredhat
Products
debian linux, ghostscript, ubuntu linux, enterprise linux desktop, enterprise linux server, enterprise linux server eus, enterprise linux workstation, gpl ghostscript
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.