Description
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1620-1 | ghostscript security update |
EUVD |
EUVD-2018-10846 | In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type. |
References
History
No history.
Subscriptions
Artifex
Subscribe
Ghostscript
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Eus
Subscribe
Enterprise Linux Workstation
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:30:03.970Z
Reserved: 2018-11-09T00:00:00.000Z
Link: CVE-2018-19134
No data.
Status : Modified
Published: 2018-12-20T23:29:00.910
Modified: 2024-11-21T03:57:23.853
Link: CVE-2018-19134
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD