SB2018112220 - Security restrictions bypass in ghostscript (Alpine package)



SB2018112220 - Security restrictions bypass in ghostscript (Alpine package)

Published: November 22, 2018

Security Bulletin ID SB2018112220
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2018-19409)

The vulnerability allows a local attacker to bypass security restrictions on the target system.

The vulnerability exists due to improper checks of the LockSafetyParams device parameter if another device is used as the top device. A local attacker can make a .setdevice call and bypass security restrictions If another device, such as the pdf14 compositor, is the top device on the system.


Remediation

Install update from vendor's website.