CVE-2018-16585
Summary
| CVE | CVE-2018-16585 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-06 14:29:00 UTC |
| Updated | 2023-11-07 02:53:00 UTC |
| Description | ** DISPUTED ** An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. Note: A reputable source believes that the CVE is potentially a duplicate of CVE-2018-15910 as explained in Red Hat bugzilla (https://bugzilla.redhat.com/show_bug.cgi?id=1626193). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| git.ghostscript.com Git - ghostpdl.git/commitdiff |
MISC |
git.ghostscript.com |
Patch, Vendor Advisory |
| USN-3768-1: Ghostscript vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| oss-sec: Re: Re: More Ghostscript Issues: Should we disable PS coders in policy.xml by default? |
MISC |
seclists.org |
Mailing List, Patch, Third Party Advisory |
| git.ghostscript.com Git - ghostpdl.git/commitdiff |
|
git.ghostscript.com |
|
| 1626193 – (CVE-2018-16585) CVE-2018-16585 ghostscript: .setdistillerkeys PostScript command is accepted even though it is not intended for use |
MISC |
bugzilla.redhat.com |
|
| git.ghostscript.com Git - ghostpdl.git/commitdiff |
MISC |
git.ghostscript.com |
Patch, Vendor Advisory |
| GPL Ghostscript: Multiple vulnerabilities (GLSA 201811-12) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Debian -- Security Information -- DSA-4288-1 ghostscript |
DEBIAN |
www.debian.org |
Third Party Advisory |
| git.ghostscript.com Git - ghostpdl.git/commitdiff |
|
git.ghostscript.com |
|
| [SECURITY] [DLA 1504-1] ghostscript security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710304 Gentoo Linux GPL Ghostscript Multiple Vulnerabilities (GLSA 201811-12)