vendor:
Ghostscript
by:
taviso
7.5
CVSS
HIGH
Errordict vulnerability
CWE
Product Name: Ghostscript
Affected Version From: Last few versions of Ghostscript
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux (Ubuntu)
Ghostscript Errordict Vulnerability
The vulnerability allows an attacker to execute arbitrary code by exploiting an error handler in Ghostscript. By causing an executeonly procedure to stop, the attacker can expose the faulting operator to the error handler. The errordict is ignored in the -dSAFER sandbox, but filling up the stack with junk can still make the invocation of the errorhandler stop. This leaves the operand stack in an inconsistent state, allowing the attacker to execute arbitrary code.
Mitigation:
Update to gnome-desktop version 3.25.90 or later, and ensure sandboxing is enabled. Manually opening files can still trigger the vulnerability.