suse · CVE-2018-16509

Quick triage

Priority: medium Published: 2021-05-30 14:16:34 UTC Updated: 2026-04-17 15:17:36 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-16509 severity moderate: SUSE including 49 source package names (ghostscript, ghostscript-10.05.0-160000.2.2, …), 168 product×package rows across 60 product lines (SUSE Enterprise Storage 4, SUSE Liberty Linux 7, … (60 product lines)): Fixed 164, Known Not Affected 4.

Description:

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

cvelogic Threat Intelligence