CVE-2018-16510

NameCVE-2018-16510
DescriptionAn issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs908304

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ghostscript (PTS)jessie9.06~dfsg-2+deb8u7fixed
jessie (security)9.26a~dfsg-0+deb8u6fixed
stretch (security), stretch9.26a~dfsg-0+deb9u6fixed
buster, buster (security)9.27~dfsg-2+deb10u3fixed
bullseye, sid9.50~dfsg-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ghostscriptsource(unstable)9.25~dfsg-1908304
ghostscriptsourceexperimental9.25~dfsg-1~exp1
ghostscriptsourcejessie(not affected)
ghostscriptsourcestretch(not affected)

Notes

[stretch] - ghostscript <not-affected> (Introduced in 9.22)
[jessie] - ghostscript <not-affected> (vulnerable code is not present)
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ea735ba37dc0fd5f5622d031830b9a559dec1cc9
https://bugs.ghostscript.com/show_bug.cgi?id=699671

Search for package or bug name: Reporting problems