#VU16020 Security restrictions bypass in Ghostscript - CVE-2018-19409
Published: November 21, 2018 / Updated: November 22, 2018
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a local attacker to bypass security restrictions on the target system.
The vulnerability exists due to improper checks of the LockSafetyParams device parameter if another device is used as the top device. A local attacker can make a .setdevice call and bypass security restrictions If another device, such as the pdf14 compositor, is the top device on the system.