CVE-2018-16585

NameCVE-2018-16585
DescriptionAn issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1504-1, DSA-4288-1
NVD severitymedium (attack range: remote)
Debian Bugs908305

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ghostscript (PTS)jessie9.06~dfsg-2+deb8u7vulnerable
jessie (security)9.06~dfsg-2+deb8u11fixed
stretch9.20~dfsg-3.2+deb9u5fixed
stretch (security)9.25~dfsg-0+deb9u1fixed
buster, sid9.25~dfsg-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ghostscriptsource(unstable)9.25~dfsg-1medium908305
ghostscriptsourceexperimental9.25~dfsg-1~exp1medium
ghostscriptsourcejessie9.06~dfsg-2+deb8u8mediumDLA-1504-1
ghostscriptsourcestretch9.20~dfsg-3.2+deb9u4mediumDSA-4288-1

Notes

http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=1497d65039885a52b598b137dd8622bd4672f9be
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=971472c83a345a16dac9f90f91258bb22dd77f22
https://bugs.ghostscript.com/show_bug.cgi?id=699663

Search for package or bug name: Reporting problems