In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ghostscript-docUpgrade libgsUpgrade ghostscript-gtkUpgrade ghostscript-debuginfoUpgrade ghostscriptUpgrade ghostscript-cupsUpgrade libgs-devel | Feb 22, 2021 | Dec 20, 2018 |
| Centos_linux | — | Upgrade ghostscriptUpgrade ghostscript-debuginfoUpgrade ghostscript-cupsUpgrade ghostscript-develUpgrade ghostscript-gtkUpgrade ghostscript-doc | Dec 20, 2018 | Nov 27, 2018 |
| Debian | — | Upgrade ghostscript | Dec 7, 2018 | Nov 27, 2018 |
| Ghostscript | — | Upgrade to Ghostscript version 9.26 | Jan 15, 2019 | Dec 20, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Feb 22, 2019 | Dec 20, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Feb 15, 2019 | Dec 20, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Jan 9, 2019 | Dec 20, 2018 |
| Oracle_linux | — | Upgrade ghostscript-cupsUpgrade ghostscript-gtkUpgrade ghostscript-docUpgrade ghostscriptUpgrade ghostscript-devel | Dec 18, 2018 | Nov 20, 2018 |
| Redhat_linux | — | Upgrade ghostscript-debuginfoUpgrade ghostscript-develUpgrade ghostscript-cupsUpgrade ghostscript-docNo solution existsUpgrade ghostscript-gtkUpgrade ghostscript | Dec 18, 2018 | Dec 17, 2018 |
| Ubuntu | — | Upgrade ghostscript | Nov 19, 2024 | Dec 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub