In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ghostscript-docUpgrade libgsUpgrade ghostscript-cupsUpgrade ghostscript-gtkUpgrade ghostscript-debuginfoUpgrade libgs-develUpgrade ghostscript | Feb 22, 2021 | Dec 20, 2018 |
| Centos_linux | — | Upgrade ghostscript-gtkUpgrade ghostscript-cupsUpgrade ghostscript-docUpgrade ghostscript-develUpgrade ghostscript-debuginfoUpgrade ghostscript | Dec 20, 2018 | Nov 27, 2018 |
| Debian | — | Upgrade ghostscript | Dec 7, 2018 | Nov 27, 2018 |
| Ghostscript | — | Upgrade to Ghostscript version 9.26 | Jan 15, 2019 | Dec 20, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Feb 22, 2019 | Dec 20, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Feb 15, 2019 | Dec 20, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Jan 9, 2019 | Dec 20, 2018 |
| Oracle_linux | — | Upgrade ghostscript-cupsUpgrade ghostscript-gtkUpgrade ghostscriptUpgrade ghostscript-docUpgrade ghostscript-devel | Dec 18, 2018 | Nov 20, 2018 |
| Redhat_linux | — | Upgrade ghostscript-develUpgrade ghostscript-debuginfoUpgrade ghostscriptUpgrade ghostscript-gtkUpgrade ghostscript-cupsUpgrade ghostscript-docNo solution exists | Dec 18, 2018 | Dec 17, 2018 |
| Ubuntu | — | Upgrade ghostscript | Nov 19, 2024 | Dec 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub