CVE-2018-19475: High severity Artifex Ghostscript vulnerability
A vulnerability was found in Artifex Ghostscript before 9.26. The restorepagedevice function in psi/zdevice2.c allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
References: https://bugs.ghostscript.com/showbug.cgi?id=700153 https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26
Upstream Patch: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=3005fcb9bb160af199e761e03bc70a9f249a987e
Other sources
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19475?
CVE-2018-19475 has been classified as moderate severity due to bypass of access restrictions.
How do I fix CVE-2018-19475?
To fix CVE-2018-19475, upgrade Ghostscript to version 9.26 or later.
Which versions are affected by CVE-2018-19475?
CVE-2018-19475 affects Ghostscript versions prior to 9.26.
Can CVE-2018-19475 be exploited remotely?
Yes, CVE-2018-19475 can be exploited remotely by attackers to bypass access restrictions.
What software does CVE-2018-19475 impact?
CVE-2018-19475 impacts Ghostscript versions before 9.26 across various Linux distributions.