PT-2018-1530 · Artifex+5 · Artifex Ghostscript+5
Tavis Ormandy
·
Published
2018-02-21
·
Updated
2024-06-15
·
CVE-2018-15911
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Artifex Ghostscript versions prior to 9.23
Description
The issue is caused by the use of uninitialized memory when manipulating the
aesdecode operator in PostScript files. This can be exploited by attackers who supply crafted PostScript files, potentially allowing them to crash the interpreter or execute arbitrary code. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.Recommendations
For Artifex Ghostscript versions prior to 9.23, update to version 9.23 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
aesdecode operator in PostScript files until a patch is applied. Avoid using crafted PostScript files that could exploit the uninitialized memory access in the aesdecode operator.Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Artifex Ghostscript
Centos
Red Hat
Suse
Ubuntu