Code injection in Ghostscript - CVE-2018-18284
Published: October 22, 2018 / Updated: April 22, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass the sandbox protection mechanism on the target system.
The vulnerability exists due to the failure of the sandbox protection mechanism of the affected software when the 1Policy operator is used. A remote unauthenticated attacker can trick the victim into accessing a PostScript file that submits malicious input, bypass the sandbox protection mechanism and modify or replace error handlers used by the software, which the attacker could use to inject and execute arbitrary code on the system.
Affected software
Arch Linux
Debian Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Opensuse
Fedora
ghostscript (Alpine package)
ghostscript
Ivanti Connect Secure (formerly Pulse Connect Secure)
EMC Cloud Tiering Appliance
How to mitigate CVE-2018-18284
ghostscript (Alpine package) - update to 9.25-r1
ghostscript - addressed in versions 9.26-1.fc28, 9.26-1.fc29
EMC Cloud Tiering Appliance - update to 12.1.0.65
External References
Related Security Bulletins
- Code injection in Artifex Ghostscript
- Arch Linux update for ghostscript
- Arch Linux update for ghostscript
- Debian update for ghostscript
- OpenSUSE Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- Red Hat update for ghostscript
- Multiple vulnerabilities in Pulse Connect Secure and Pulse Policy Secure
- Code injection in ghostscript (Alpine package)
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- Fedora 29 update for ghostscript
- Fedora 28 update for ghostscript