An issue was discovered in Artifex Ghostscript before 9.25. Incorrect restoration of privilege checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the pipe instruction. This is due to an incomplete fix for CVE-2018-16509.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ghostscript | Artifex | * | 9.25 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | ghostscript-0:9.07-31.el7_6.6 | * |
Ghostscript | Ubuntu | bionic | * |
Ghostscript | Ubuntu | devel | * |
Ghostscript | Ubuntu | trusty | * |
Ghostscript | Ubuntu | xenial | * |