Related Vulnerabilities: CVE-2018-18073  

Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.

Severity High

Remote Yes

Type Sandbox escape

Description

Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.

AVG-786 ghostscript 9.25-3 9.25-4 High Fixed

06 Nov 2018 ASA-201811-3 AVG-786 ghostscript High sandbox escape

https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=34cc326eb2c5695833361887fe0b32e8d987741c
http://packetstormsecurity.com/files/149758/Ghostscript-Exposed-System-Operators.html
http://www.openwall.com/lists/oss-security/2018/10/10/12