PT-2018-2507 · Artifex+5 · Ghostscript+5

Man Yue Mo

·

Published

2018-11-14

·

Updated

2024-06-15

·

CVE-2018-19477

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostscript versions prior to 9.26
Description The issue is related to a type confusion in JBIG2Decode, allowing remote attackers to bypass intended access restrictions. This is due to errors in the JBIG2Decode type.
Recommendations For Ghostscript versions prior to 9.26, update to version 9.26 or later to resolve the issue.

Exploit

Fix

Type Confusion

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2799
BDU:2019-00877
CESA-2019_0229
CVE-2018-19477
DLA-1598-1
DSA-4346-1
DSA-4346-2
OPENSUSE-SU-2018_4138-1
OPENSUSE-SU-2018_4140-1
OPENSUSE-SU-2024:10783-1
RHSA-2019:0229
RHSA-2019_0229
SUSE-SU-2018:4087-1
SUSE-SU-2018:4090-1
SUSE-SU-2018:4090-2
USN-3831-1
USN-3831-2

Affected Products

Alt Linux
Centos
Ghostscript
Red Hat
Suse
Ubuntu