Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16543

Опубликовано: 06 сент. 2018
Источник: redhat
CVSS3: 7.3

Описание

In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

It was discovered that the ghostscript gssetresolution and gsgetresolution procedures were available, although they have dangerous side effects. An attacker could possibly exploit this to bypass the -dSAFER protection and crash ghostscript or, possibly, execute arbitrary code in the ghostscript context via a specially crafted PostScript document.

Отчет

CVE-2018-16543 requires the "device subclassing" feature to be present in ghostscript in order to exploit it and corrupt the interpreter's memory. This feature appeared in Ghostscript-9.18. Thus ghostscript 9.07, as shipped in Red Hat Enterprise Linux 7, and older are not affected : although the attacker has access to the gssetresolution and gsgetresolution operators, they can not use these to corrupt memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ghostscriptNot affected
Red Hat Enterprise Linux 6ghostscriptNot affected
Red Hat Enterprise Linux 7ghostscriptNot affected
Red Hat Enterprise Linux 8ghostscriptNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-561
https://bugzilla.redhat.com/show_bug.cgi?id=1625851ghostscript: gssetresolution and gsgetresolution memory corruption (699670)

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

CVSS3: 7.8
nvd
больше 7 лет назад

In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

CVSS3: 7.8
debian
больше 7 лет назад

In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolutio ...

CVSS3: 7.8
github
больше 3 лет назад

In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

CVSS3: 7.8
fstec
больше 7 лет назад

Уязвимость компонентов gssetresolution и gsgetresolution набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

7.3 High

CVSS3