Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10194

Опубликовано: 18 апр. 2018
Источник: debian
EPSS Низкий

Описание

The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ghostscriptfixed9.22~dfsg-2.1package
ghostscriptfixed9.20~dfsg-3.2+deb9u2stretchpackage
ghostscriptfixed9.06~dfsg-2+deb8u7jessiepackage

Примечания

  • https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=39b1e54b2968620723bf32e96764c88797714879

  • https://bugs.ghostscript.com/show_bug.cgi?id=699255 (not yet public)

EPSS

Процентиль: 70%
0.00648
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

CVSS3: 7
redhat
больше 7 лет назад

The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

CVSS3: 7.8
nvd
больше 7 лет назад

The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

suse-cvrf
больше 7 лет назад

Security update for ghostscript

suse-cvrf
больше 7 лет назад

Security update for ghostscript

EPSS

Процентиль: 70%
0.00648
Низкий