CVE-2018-16509
84Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 92%
from disclosure to weapon5 days
Published on NVDSep 5
1st PoC+5d
metasploitAug 21
VulnCheck+2074d
exploitation probability
92%top 1% of all CVEs
observed exploitation
yesVulnCheck
7 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
1 product
Red Hat Enterprise Linux 5
workaround: * ImageMagick relies on ghostscript when processing certain files formats. Thus, ImageMagick can be used as an attack vector. In order to prevent ImageMagick from processing those files on Red Hat Enterprise Linux 6 and 7…
Fixed
18 products (576 components)
Red Hat Enterprise Linux Client (v. 7) · Red Hat Enterprise Linux Client Optional (v. 7) · Red Hat Enterprise Linux ComputeNode (v. 7) · Red Hat Enterprise Linux ComputeNode Optional (v. 7) · Red Hat Enterprise Linux Server (v. 7) · and others 13
Not affected
12 products (26 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 8 · Red Hat OpenShift Container Platform 3.10 · Red Hat OpenShift Container Platform 3.11 · Red Hat OpenShift Enterprise 3.1 · Red Hat OpenShift Container Platform 3.2 · and others 7
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
Affected products
n/a · n/apublic PoCs found — 7✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45369githubgithub.com/farisv/PIL-RCE-Ghostscript-CVE-2018-16509★ 62githubgithub.com/knqyf263/CVE-2018-16509★ 3githubgithub.com/rhpco/CVE-2018-16509★ 1githubgithub.com/cved-sources/cve-2018-16509★ 0cve_referencewww.exploit-db.com/exploits/45369/unverifiedvulncheckvulncheck.com/xdb/cb9953ec760cunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=5516c614dc33662a2afdc377159f70218e67bde5http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=78911a01b67d590b4a91afac2e8417360b934156http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=79cccf641486a6595c43f1de1cd7ade696020a31http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=520bb0ea7519aa3e79db78aaf0589dae02103764https://access.redhat.com/errata/RHSA-2018:2918https://access.redhat.com/errata/RHSA-2018:3760https://bugs.ghostscript.com/show_bug.cgi?id=699654http://seclists.org/oss-sec/2018/q3/142https://lists.debian.org/debian-lts-announce/2018/09/msg00015.htmlhttps://security.gentoo.org/glsa/201811-12https://usn.ubuntu.com/3768-1/https://www.artifex.com/news/ghostscript-security-resolved/