CVE-2018-18073 - log back

CVE-2018-18073 created at 25 Sep 2019 19:31:40
Severity
+ High
Remote
+ Remote
Type
+ Sandbox escape
Description
+ Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.
References
+ https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=34cc326eb2c5695833361887fe0b32e8d987741c
+ http://packetstormsecurity.com/files/149758/Ghostscript-Exposed-System-Operators.html
+ http://www.openwall.com/lists/oss-security/2018/10/10/12
Notes