Code injection in Ghostscript - CVE-2018-18284

 

Code injection in Ghostscript - CVE-2018-18284

Published: October 22, 2018 / Updated: April 22, 2020


Vulnerability identifier: #VU15463
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-18284
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass the sandbox protection mechanism on the target system.

The vulnerability exists due to the failure of the sandbox protection mechanism of the affected software when the 1Policy operator is used. A remote unauthenticated attacker can trick the victim into accessing a PostScript file that submits malicious input, bypass the sandbox protection mechanism and modify or replace error handlers used by the software, which the attacker could use to inject and execute arbitrary code on the system.


Affected software

Ghostscript
Arch Linux
Debian Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Opensuse
Fedora
ghostscript (Alpine package)
ghostscript
Ivanti Connect Secure (formerly Pulse Connect Secure)
EMC Cloud Tiering Appliance

How to mitigate CVE-2018-18284

Install update from vendor's website.

Ivanti Connect Secure (formerly Pulse Connect Secure) - addressed in versions 8.2R12.1, 8.3R7.1, 9.0R3.4
ghostscript (Alpine package) - update to 9.25-r1
ghostscript - addressed in versions 9.26-1.fc28, 9.26-1.fc29
EMC Cloud Tiering Appliance - update to 12.1.0.65

External References

Related Security Bulletins