Remote Code Injection Vulnerability in Ghostscript by Artifex
CVE-2018-17183

7.8HIGH

Key Information:

Vendor
Debian
Vendor
CVE Published:
19 September 2018

Summary

Artifex Ghostscript versions prior to 9.25 have a significant vulnerability that allows remote attackers to exploit a user-writable error exception table. By submitting specially crafted PostScript files, malicious users could overwrite or replace existing error handlers. This vulnerability facilitates potential code injection, raising concerns for the integrity and security of systems utilizing Ghostscript.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.