PT-2018-13620 · Artifex+5 · Ghostscript+5

Tavis Ormandy

·

Published

2018-09-05

·

Updated

2024-06-15

·

CVE-2018-16541

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions prior to 9.24
Description The issue arises from incorrect free logic in pagedevice replacement, allowing attackers who can supply crafted PostScript files to crash the interpreter.
Recommendations For versions prior to 9.24, update to version 9.24 or later to resolve the issue.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2344
CESA-2018_3834
CVE-2018-16541
DLA-1504-1
DSA-4288-1
MGASA-2018-0378
OPENSUSE-SU-2018:3687-1
OPENSUSE-SU-2018_3036-1
OPENSUSE-SU-2018_3038-1
OPENSUSE-SU-2018_3051-1
OPENSUSE-SU-2024:10783-1
RHSA-2018:3834
RHSA-2018_3834
SUSE-SU-2018:2975-1
SUSE-SU-2018:2975-2
SUSE-SU-2018:2975-3
SUSE-SU-2018:2976-1
SUSE-SU-2018:3330-1
USN-3768-1

Affected Products

Alt Linux
Centos
Ghostscript
Red Hat
Suse
Ubuntu