Improper input validation in Ghostscript - CVE-2018-15909

 

Improper input validation in Ghostscript - CVE-2018-15909

Published: August 23, 2018 / Updated: April 22, 2020


Vulnerability identifier: #VU14496
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15909
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions and execute arbitrary system commands.

The vulnerability exists due to improper input validation when processing malformed PostScript, PDF, EPS, or XPS files. A remote attacker can supply a specially crafted file, bypass -dSAFER restrictions and execute arbitrary commands on vulnerable system.



Affected software

Ghostscript
ghostscript (Alpine package)
ghostscript
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power
Fedora
Ivanti Connect Secure (formerly Pulse Connect Secure)

How to mitigate CVE-2018-15909

Install update from vendor's website.

Ghostscript - update to 9.24
Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 8.2R12.1, 8.3R7.1, 9.0R3.4
ghostscript (Alpine package) - update to 9.24-r0
ghostscript - addressed in versions 9.23-6.fc28, 9.23-7.fc29

External References

Related Security Bulletins