CVE-2018-16510

NameCVE-2018-16510
DescriptionAn issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs908304

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ghostscript (PTS)jessie, jessie (lts)9.26a~dfsg-0+deb8u12fixed
stretch (security)9.26a~dfsg-0+deb9u9fixed
stretch (lts), stretch9.26a~dfsg-0+deb9u12fixed
buster (security), buster, buster (lts)9.27~dfsg-2+deb10u9fixed
bullseye9.53.3~dfsg-7+deb11u7fixed
bullseye (security)9.53.3~dfsg-7+deb11u8fixed
bookworm10.0.0~dfsg-11+deb12u5fixed
bookworm (security)10.0.0~dfsg-11+deb12u6fixed
sid, trixie10.04.0~dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ghostscriptsourceexperimental9.25~dfsg-1~exp1
ghostscriptsourcewheezy(unfixed)end-of-life
ghostscriptsourcejessie(not affected)
ghostscriptsourcestretch(not affected)
ghostscriptsource(unstable)9.25~dfsg-1908304

Notes

[stretch] - ghostscript <not-affected> (Introduced in 9.22)
[jessie] - ghostscript <not-affected> (vulnerable code is not present)
https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ea735ba37dc0fd5f5622d031830b9a559dec1cc9
https://bugs.ghostscript.com/show_bug.cgi?id=699671

Search for package or bug name: Reporting problems