#VU16020 Security restrictions bypass in Ghostscript - CVE-2018-19409 

 

#VU16020 Security restrictions bypass in Ghostscript - CVE-2018-19409

Published: November 21, 2018 / Updated: November 22, 2018


Vulnerability identifier: #VU16020
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-19409
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Ghostscript
Software vendor:
Artifex Software, Inc.

Description

The vulnerability allows a local attacker to bypass security restrictions on the target system.

The vulnerability exists due to improper checks of the LockSafetyParams device parameter if another device is used as the top device. A local attacker can make a .setdevice call and bypass security restrictions If another device, such as the pdf14 compositor, is the top device on the system.


Remediation

Update to version 9.26.

External links