SB2018112220 - Security restrictions bypass in ghostscript (Alpine package)
Published: November 22, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2018-19409)
The vulnerability allows a local attacker to bypass security restrictions on the target system.
The vulnerability exists due to improper checks of the LockSafetyParams device parameter if another device is used as the top device. A local attacker can make a .setdevice call and bypass security restrictions If another device, such as the pdf14 compositor, is the top device on the system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=9096cb46474180811d360209f21d51206ce31580
- https://git.alpinelinux.org/aports/commit/?id=b0243d03648d68851d3b5edb68da29eaae5c9f0f
- https://git.alpinelinux.org/aports/commit/?id=b38a11ee1f5109ffc2f67afa52903b9437dd4111
- https://git.alpinelinux.org/aports/commit/?id=1effb87543c10d5de5e0a181c6757a0d5cf9e599
- https://git.alpinelinux.org/aports/commit/?id=6d86206da24de4fa211d069ae110b32ffd41e1ac
- https://git.alpinelinux.org/aports/commit/?id=90f284afbeec1f422dc08dc966719005e5def79a
- https://git.alpinelinux.org/aports/commit/?id=d58edba21f19cbfda556148ab655755ccde6e857
- https://git.alpinelinux.org/aports/commit/?id=e558a52ec2ce576ebfe50d2acaee3449d1ef6c26