CVE-2018-16510
Last modified
CVE-2018-16510 is a vulnerability of currently unknown severity. An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.. EPSS estimates a 1.75% chance of exploitation in the next 30 days.
Description
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Ghostscript | < 9.24 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Artifex | Gpl Ghostscript | < 9.26 |
References
- http://openwall.com/lists/oss-security/2018/08/27/4Issue Tracking, Mailing List, Patch, Third Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=699671Issue Tracking, Permissions Required
- https://security.gentoo.org/glsa/201811-12Third Party Advisory
- https://usn.ubuntu.com/3768-1/Third Party Advisory
- https://usn.ubuntu.com/3773-1/Third Party Advisory
- http://openwall.com/lists/oss-security/2018/08/27/4Issue Tracking, Mailing List, Patch, Third Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=699671Issue Tracking, Permissions Required
- https://security.gentoo.org/glsa/201811-12Third Party Advisory
- https://usn.ubuntu.com/3768-1/Third Party Advisory
- https://usn.ubuntu.com/3773-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16510?
How severe is CVE-2018-16510?
How do I fix CVE-2018-16510?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-16496In Versa Director, the un-authentication request found.5.3
- CVE-2018-16497In Versa Analytics, the cron jobs are used for scheduling ta…7.8
- CVE-2018-16498In Versa Director, the unencrypted backup files stored on th…5.5
- CVE-2018-16499In VOS compromised, an attacker at network endpoints can pos…5.9
- CVE-2018-1650IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials whic…5.9
- CVE-2018-16509An issue was discovered in Artifex Ghostscript before 9.24. …
- CVE-2018-16511An issue was discovered in Artifex Ghostscript before 9.24. …
- CVE-2018-16513In Artifex Ghostscript before 9.24, attackers able to supply…
- CVE-2018-16514A cross-site scripting (XSS) vulnerability in the View Filte…
- CVE-2018-16515Matrix Synapse before 0.33.3.1 allows remote attackers to sp…
- CVE-2018-16516helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a craf…
- CVE-2018-16517asm/labels.c in Netwide Assembler (NASM) is prone to NULL Po…5.5
Are you affected by CVE-2018-16510?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
