Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ghostscript | Aug 22, 2024 | Oct 19, 2018 |
| Amazon Linux Ami 2 | — | Upgrade ghostscript-debuginfoUpgrade ghostscript-docUpgrade ghostscriptUpgrade libgsUpgrade libgs-develUpgrade ghostscript-gtkUpgrade ghostscript-cups | Feb 22, 2021 | Oct 19, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 19, 2018 |
| Centos_linux | — | Upgrade ghostscript-debuginfoUpgrade ghostscript-gtkUpgrade ghostscript-cupsUpgrade ghostscript-docUpgrade ghostscriptUpgrade ghostscript-devel | Dec 20, 2018 | Oct 19, 2018 |
| Debian | — | Upgrade ghostscript | Nov 11, 2018 | Oct 19, 2018 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Nov 26, 2018 | Oct 19, 2018 |
| Ghostscript | — | Upgrade to Ghostscript version 9.26 | Nov 27, 2018 | Oct 19, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Feb 22, 2019 | Oct 19, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Feb 15, 2019 | Oct 19, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Jan 9, 2019 | Oct 19, 2018 |
| Oracle Solaris | — | Upgrade print/filter/ghostscript to version 9.26-0.175.3.36.0.10.0 on Solaris 11.3Upgrade print/filter/ghostscript/fonts/gnu-gs-fonts-other to version 6.0-11.4.5.0.1.2.0 on Solaris 11.4Upgrade print/filter/ghostscript-core to version 9.26-11.4.5.0.1.2.0 on Solaris 11.4Upgrade print/filter/ghostscript/fonts/gnu-gs-fonts-std to version 8.11-11.4.5.0.1.2.0 on Solaris 11.4Upgrade print/filter/ghostscript to version 9.26-11.4.5.0.1.2.0 on Solaris 11.4 | Feb 20, 2019 | Oct 19, 2018 |
| Oracle_linux | — | Upgrade ghostscript-gtkUpgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-docUpgrade ghostscript-cups | Dec 18, 2018 | Oct 12, 2018 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.1R15.1Update Pulse Connect Secure to version 8.2R12.1Update Pulse Connect Secure to version 8.3R7.1Update Pulse Connect Secure to version 9.0R4 | Oct 28, 2020 | Oct 19, 2018 |
| Redhat_linux | — | Upgrade ghostscript-gtkUpgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-docUpgrade ghostscript-debuginfoUpgrade ghostscript-cupsNo solution exists | Dec 18, 2018 | Oct 19, 2018 |
| Suse | — | Upgrade ghostscript-mini-develUpgrade ghostscript-develUpgrade ghostscriptUpgrade ghostscript-x11Upgrade ghostscript-miniUpgrade libspectre1Upgrade libspectre-devel | Dec 13, 2018 | Oct 19, 2018 |
| Ubuntu | — | Upgrade ghostscriptUpgrade libgs9 | Nov 7, 2018 | Oct 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub