CVE Vulnerabilities

CVE-2018-19475

Published: Nov 23, 2018 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.3 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

Affected Software

Name Vendor Start Version End Version
Ghostscript Artifex * 9.26 (excluding)
Red Hat Enterprise Linux 7 RedHat ghostscript-0:9.07-31.el7_6.9 *
Ghostscript Ubuntu bionic *
Ghostscript Ubuntu cosmic *
Ghostscript Ubuntu devel *
Ghostscript Ubuntu trusty *
Ghostscript Ubuntu upstream *
Ghostscript Ubuntu xenial *

References