Privilege Escalation via Incomplete Fix for CVE-2018-16509 in Artifex Ghostscript

Privilege Escalation via Incomplete Fix for CVE-2018-16509 in Artifex Ghostscript

CVE-2018-16802 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.

Learn more about our Web Application Penetration Testing UK.