PT-2018-2506 · Artifex+5 · Ghostscript+5

Publicado

2018-11-14

·

Atualizado

2024-06-15

·

CVE-2018-19476

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostscript versions prior to 9.26
Description The issue is related to a type confusion in the setcolorspace, allowing remote attackers to bypass intended access restrictions. This is due to errors in the setcolorspace type. The exploitation of this issue may enable a remote attacker to circumvent established access control.
Recommendations For Ghostscript versions prior to 9.26, update to version 9.26 or later to resolve the issue.

Exploit

Correção

Type Confusion

Incorrect Type Conversion or Cast

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2799
BDU:2019-00876
BDU:2019-00877
CESA-2019_0229
CVE-2018-19476
DLA-1598-1
DSA-4346-1
DSA-4346-2
OPENSUSE-SU-2018_4138-1
OPENSUSE-SU-2018_4140-1
OPENSUSE-SU-2024:10783-1
RHSA-2019:0229
RHSA-2019_0229
SUSE-SU-2018:4087-1
SUSE-SU-2018:4090-1
SUSE-SU-2018:4090-2
USN-3831-1
USN-3831-2

Produtos afetados

Alt Linux
Centos
Ghostscript
Red Hat
Suse
Ubuntu