Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
http://git.ghostscript.com/?p=ghostpdl.git;h=8d19fdf63f91f50466b08f23e2d93d37a4c5ea0b
http://www.openwall.com/lists/oss-security/2018/10/16/2
http://www.securityfocus.com/bid/107451
https://access.redhat.com/errata/RHSA-2018:3834
https://bugs.chromium.org/p/project-zero/issues/detail?id=1696
https://bugs.ghostscript.com/show_bug.cgi?id=699963
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101
https://lists.debian.org/debian-lts-announce/2018/10/msg00013.html
https://security.gentoo.org/glsa/201811-12
https://support.f5.com/csp/article/K22141757?utm_source=f5support&utm_medium=RSS
Source: MITRE
Published: 2018-10-19
Updated: 2019-11-05
Type: NVD-CWE-noinfo
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 8.6
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Impact Score: 6
Exploitability Score: 1.8
Severity: HIGH
OR
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:* versions up to 9.25 (inclusive)
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
OR
OR
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
OR
cpe:2.3:a:pulsesecure:pulse_connect_secure:*:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
146633 | Amazon Linux 2 : ghostscript (ALAS-2021-1598) | Nessus | Amazon Linux Local Security Checks | high |
127227 | NewStart CGSL CORE 5.04 / MAIN 5.04 : ghostscript Multiple Vulnerabilities (NS-SA-2019-0046) | Nessus | NewStart CGSL Local Security Checks | high |
124887 | EulerOS Virtualization for ARM 64 3.0.1.0 : ghostscript (EulerOS-SA-2019-1384) | Nessus | Huawei Local Security Checks | high |
124766 | Pulse Connect Secure Multiple Vulnerabilities (SA44101) | Nessus | Misc. | high |
123895 | EulerOS Virtualization 2.5.4 : ghostscript (EulerOS-SA-2019-1209) | Nessus | Huawei Local Security Checks | high |
123891 | EulerOS Virtualization 2.5.3 : ghostscript (EulerOS-SA-2019-1205) | Nessus | Huawei Local Security Checks | high |
123151 | openSUSE Security Update : ghostscript (openSUSE-2019-1007) | Nessus | SuSE Local Security Checks | high |
122376 | EulerOS 2.0 SP2 : ghostscript (EulerOS-SA-2019-1049) | Nessus | Huawei Local Security Checks | high |
122284 | Fedora 28 : ghostscript (2019-82acb29c1b) | Nessus | Fedora Local Security Checks | high |
122169 | EulerOS 2.0 SP3 : ghostscript (EulerOS-SA-2019-1022) | Nessus | Huawei Local Security Checks | high |
122103 | Fedora 29 : ghostscript (2019-077a3f23c0) | Nessus | Fedora Local Security Checks | high |
121276 | EulerOS Virtualization 2.5.1 : ghostscript (EulerOS-SA-2019-1016) | Nessus | Huawei Local Security Checks | high |
120992 | EulerOS 2.0 SP5 : ghostscript (EulerOS-SA-2019-1004) | Nessus | Huawei Local Security Checks | high |
120186 | SUSE SLED15 / SLES15 Security Update : ghostscript (SUSE-SU-2018:4087-1) | Nessus | SuSE Local Security Checks | high |
119901 | EulerOS Virtualization 2.5.2 : ghostscript (EulerOS-SA-2018-1412) | Nessus | Huawei Local Security Checks | high |
119883 | Scientific Linux Security Update : ghostscript on SL7.x x86_64 (20181217) | Nessus | Scientific Linux Local Security Checks | high |
119757 | Oracle Linux 7 : ghostscript (ELSA-2018-3834) | Nessus | Oracle Linux Local Security Checks | high |
119754 | CentOS 7 : ghostscript (CESA-2018:3834) | Nessus | CentOS Local Security Checks | high |
119736 | RHEL 7 : ghostscript (RHSA-2018:3834) | Nessus | Red Hat Local Security Checks | high |
119713 | openSUSE Security Update : ghostscript (openSUSE-2018-1556) | Nessus | SuSE Local Security Checks | high |
119711 | openSUSE Security Update : ghostscript (openSUSE-2018-1552) | Nessus | SuSE Local Security Checks | high |
119651 | SUSE SLED12 / SLES12 Security Update : ghostscript (SUSE-SU-2018:4090-1) | Nessus | SuSE Local Security Checks | high |
119132 | GLSA-201811-12 : GPL Ghostscript: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
118893 | Debian DSA-4336-1 : ghostscript - security update | Nessus | Debian Local Security Checks | medium |
118567 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : Ghostscript vulnerabilities (USN-3803-1) | Nessus | Ubuntu Local Security Checks | medium |
118313 | Debian DLA-1552-1 : ghostscript security update | Nessus | Debian Local Security Checks | medium |