CVE-2018-17183: High severity Artifex Ghostscript vulnerability
Published Sep 19, 2018
·Updated
Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.
Affected Software
13 affected componentsFixes available
redhat/ghostscript<9.26
9.26
Artifex Ghostscript<9.25
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=7.0
debian/ghostscript
9.53.3~dfsg-7+deb11u79.53.3~dfsg-7+deb11u1110.0.0~dfsg-11+deb12u810.05.1~dfsg-1+deb13u110.06.0~dfsg-3
Remediation
Event History
Sep 19, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·04:14 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:15 PM
DescriptionAffected Software
Data Sourced
via Launchpad·04:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17183?
CVE-2018-17183 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2018-17183?
To fix CVE-2018-17183, update Ghostscript to version 9.26 or later.
3
Which versions of Ghostscript are affected by CVE-2018-17183?
CVE-2018-17183 affects Ghostscript versions prior to 9.26.
4
Can CVE-2018-17183 be exploited remotely?
Yes, CVE-2018-17183 can be exploited remotely by attackers who supply crafted PostScript.
5
What types of systems are vulnerable to CVE-2018-17183?
CVE-2018-17183 affects various systems running vulnerable versions of Ghostscript, including Red Hat and Debian installations.