Remote Code Injection Vulnerability in Ghostscript by Artifex
CVE-2018-17183
7.8HIGH
Key Information:
- Vendor
- Debian
- Vendor
- CVE Published:
- 19 September 2018
Summary
Artifex Ghostscript versions prior to 9.25 have a significant vulnerability that allows remote attackers to exploit a user-writable error exception table. By submitting specially crafted PostScript files, malicious users could overwrite or replace existing error handlers. This vulnerability facilitates potential code injection, raising concerns for the integrity and security of systems utilizing Ghostscript.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved