In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ghostscriptUpgrade ghostscript-docUpgrade ghostscript-develUpgrade ghostscript-cupsUpgrade ghostscript-gtkUpgrade ghostscript-debuginfo | Apr 27, 2020 | Sep 5, 2018 |
| Debian | — | Upgrade ghostscript | Sep 9, 2018 | Sep 5, 2018 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Nov 26, 2018 | Sep 5, 2018 |
| Ghostscript | — | Upgrade to Ghostscript version 9.24 | Oct 10, 2018 | Sep 5, 2018 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.2R12.1Update Pulse Connect Secure to version 8.1R15.1Update Pulse Connect Secure to version 8.3R7.1Update Pulse Connect Secure to version 9.0R4 | Oct 28, 2020 | Sep 5, 2018 |
| Suse | — | Upgrade ghostscript-fonts-rusUpgrade ghostscript-develUpgrade ghostscript-omniUpgrade ghostscript-mini-develUpgrade ghostscriptUpgrade ghostscript-miniUpgrade libspectre-develUpgrade libspectre1Upgrade ghostscript-fonts-otherUpgrade ghostscript-ijs-develUpgrade libgimpprintUpgrade ghostscript-x11Upgrade libgimpprint-develUpgrade ghostscript-libraryUpgrade ghostscript-fonts-std | Oct 3, 2018 | Sep 5, 2018 |
| Ubuntu | — | Upgrade ghostscriptUpgrade libgs9 | Oct 2, 2018 | Sep 5, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub