peter bassill · operator
$ cve CVE-2018-17961 JSON

CVE-2018-17961 EXPLOIT

8.6
HIGH · CVSS 3.0 · EPSS 10% (pctl 95)

Patch early

A public exploit exists.

Description

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.

Scoring

CVSS8.6 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS9.98% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-209
On CISA KEVno
Public exploityes
Published2018-10-15
Last modified2026-06-17

Affected (9)

VendorProduct
artifexghostscript
canonicalubuntu linux
debiandebian linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD