Name | CVE-2018-16510 |
Description | An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 908304 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
ghostscript (PTS) | jessie, jessie (lts) | 9.26a~dfsg-0+deb8u12 | fixed |
| stretch (security) | 9.26a~dfsg-0+deb9u9 | fixed |
| stretch (lts), stretch | 9.26a~dfsg-0+deb9u12 | fixed |
| buster (security), buster, buster (lts) | 9.27~dfsg-2+deb10u9 | fixed |
| bullseye | 9.53.3~dfsg-7+deb11u7 | fixed |
| bullseye (security) | 9.53.3~dfsg-7+deb11u8 | fixed |
| bookworm | 10.0.0~dfsg-11+deb12u5 | fixed |
| bookworm (security) | 10.0.0~dfsg-11+deb12u6 | fixed |
| sid, trixie | 10.04.0~dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[stretch] - ghostscript <not-affected> (Introduced in 9.22)
[jessie] - ghostscript <not-affected> (vulnerable code is not present)
https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ea735ba37dc0fd5f5622d031830b9a559dec1cc9
https://bugs.ghostscript.com/show_bug.cgi?id=699671