Security restrictions bypass in Ghostscript - CVE-2018-19409

 

Security restrictions bypass in Ghostscript - CVE-2018-19409

Published: November 21, 2018 / Updated: November 22, 2018


Vulnerability identifier: #VU16020
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19409
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass security restrictions on the target system.

The vulnerability exists due to improper checks of the LockSafetyParams device parameter if another device is used as the top device. A local attacker can make a .setdevice call and bypass security restrictions If another device, such as the pdf14 compositor, is the top device on the system.


Affected software

Ghostscript
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Fedora
ghostscript (Alpine package)
ghostscript
EMC Cloud Tiering Appliance

How to mitigate CVE-2018-19409

Update to version 9.26.

Ghostscript - update to 9.26
ghostscript (Alpine package) - update to 9.26-r0
ghostscript - addressed in versions 9.26-1.fc28, 9.26-1.fc29
EMC Cloud Tiering Appliance - update to 12.1.0.65

External References

Related Security Bulletins