CVE-2018-19409

Name
CVE-2018-19409
Description
An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Release Notes https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26
Patch https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=661e8d8fb8248c38d67958beda32f3a5876d0c3f
Issue Tracking https://bugs.ghostscript.com/show_bug.cgi?id=700176
Third Party Advisory http://www.securityfocus.com/bid/105990
Mitigation https://security.gentoo.org/glsa/201811-12
Third Party Advisory https://www.debian.org/security/2018/dsa-4346
Third Party Advisory https://lists.debian.org/debian-lts-announce/2018/11/msg00036.html
Third Party Advisory https://usn.ubuntu.com/3831-1/
Third Party Advisory https://access.redhat.com/errata/RHSA-2018:3834

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:* ghostscript >= None < 9.26

Vulnerable and fixed packages

Source package Branch Version Maintainer Status