#VU15375 Code Injection in Ghostscript - CVE-2018-17183
Published: October 16, 2018
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the application allowed a user-writable error exception table. A remote attacker can use a specially crafted PostScript file to overwrite error handlers and inject arbitrary code.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.