CVE Vulnerabilities

CVE-2018-19475

Published: Nov 23, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.3 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

Affected Software

NameVendorStart VersionEnd Version
GhostscriptArtifex*9.26 (excluding)
Red Hat Enterprise Linux 7RedHatghostscript-0:9.07-31.el7_6.9*
GhostscriptUbuntubionic*
GhostscriptUbuntucosmic*
GhostscriptUbuntudevel*
GhostscriptUbuntuesm-infra/bionic*
GhostscriptUbuntuesm-infra/xenial*
GhostscriptUbuntutrusty*
GhostscriptUbuntuupstream*
GhostscriptUbuntuxenial*

References