ALPINE-CVE-2018-15909 PUBLISHED CVSS 7.800000190734863 HIGH

In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.

Risk Scores

CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.7ghostscript9.21-r3, 9.22-r0, 9.21-r3
Alpine:v3.17ghostscript9.22-r0, 8.64-r0, 8.70-r0
Alpine:v3.8ghostscript0, 9.22-r0, 9.21-r3
Alpine:v3.9ghostscript0, 8.64-r0, 8.70-r0
Alpine:v3.19ghostscript8.71-r0, 0, 8.64-r0
Alpine:v3.5ghostscript9.19-r0, 0, 8.64-r0
Alpine:v3.13ghostscript9.20-r0, 0, 8.64-r0
Alpine:v3.22ghostscript9.00-r0, 9.22-r0, 9.21-r3
Alpine:v3.10ghostscript9.09-r0, 9.22-r0, 9.21-r3
Alpine:v3.20ghostscript9.18-r0, 9.16-r2, 9.16-r1
Alpine:v3.11ghostscript9.00-r0, 9.00-r2, 9.04-r0
Alpine:v3.14ghostscript9.18-r0, 0, 9.16-r2
Alpine:v3.15ghostscript9.00-r1, 9.21-r3, 9.21-r2
Alpine:v3.21ghostscript9.06-r1, 0, 8.64-r0
Alpine:v3.12ghostscript8.71-r4, 8.71-r3, 8.71-r2
Alpine:v3.23ghostscript9.21-r2, 9.06-r0, 9.05-r1
Alpine:v3.6ghostscript9.10-r0, 0, 8.64-r0
Alpine:v3.16ghostscript0, 9.22-r0, 9.21-r3
Alpine:v3.18ghostscript9.22-r0, 9.21-r3, 9.21-r2

Timeline

References

Open in Interactive Console →