Improper input validation in Ghostscript - CVE-2018-15909
Published: August 23, 2018 / Updated: April 22, 2020
Ghostscript
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass implemented security restrictions and execute arbitrary system commands.
The vulnerability exists due to improper input validation when processing malformed PostScript, PDF, EPS, or XPS files. A remote attacker can supply a specially crafted file, bypass -dSAFER restrictions and execute arbitrary commands on vulnerable system.