CVE-2018-16510

NameCVE-2018-16510
DescriptionAn issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs908304

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ghostscript (PTS)stretch9.26a~dfsg-0+deb9u6fixed
stretch (security)9.26a~dfsg-0+deb9u7fixed
buster, buster (security)9.27~dfsg-2+deb10u4fixed
bullseye9.52.1~dfsg-1fixed
sid9.53.2~dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ghostscriptsourceexperimental9.25~dfsg-1~exp1
ghostscriptsourcejessie(not affected)
ghostscriptsourcestretch(not affected)
ghostscriptsource(unstable)9.25~dfsg-1908304

Notes

[stretch] - ghostscript <not-affected> (Introduced in 9.22)
[jessie] - ghostscript <not-affected> (vulnerable code is not present)
https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ea735ba37dc0fd5f5622d031830b9a559dec1cc9
https://bugs.ghostscript.com/show_bug.cgi?id=699671

Search for package or bug name: Reporting problems