PT-2018-2554 · Artifex+5 · Artifex Ghostscript+5

Tavis Ormandy

·

Published

2018-08-21

·

Updated

2024-06-15

·

CVE-2018-16511

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions prior to 9.24
Description The issue is related to a type confusion in ztype that could be exploited by remote attackers who can supply crafted PostScript, potentially allowing them to crash the interpreter or have other unspecified impacts. The vulnerability may also affect the confidentiality, integrity, and availability of protected information.
Recommendations For Artifex Ghostscript versions prior to 9.24, update to version 9.24 or later to resolve the issue.

Fix

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2344
BDU:2019-00972
CESA-2018_3650
CVE-2018-16511
DLA-1504-1
DSA-4288-1
MGASA-2018-0378
OPENSUSE-SU-2018_3036-1
OPENSUSE-SU-2018_3038-1
OPENSUSE-SU-2024:10783-1
RHSA-2018:3650
RHSA-2018_3650
SUSE-SU-2018:2975-1
SUSE-SU-2018:2975-2
SUSE-SU-2018:2975-3
SUSE-SU-2018:2976-1
SUSE-SU-2018:3330-1
USN-3768-1

Affected Products

Alt Linux
Artifex Ghostscript
Centos
Red Hat
Suse
Ubuntu