CVE-2018-16511

Description

An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in ztype could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.371

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Ghostscript 9.23Windows
ghostscript security update(DSA-4288-1) ghostscript_9.20~dfsg-3.2+deb9u4_i386.debLinux
ghostscript security update(DSA-4288-1) ghostscript_9.20~dfsg-3.2+deb9u4_amd64.debLinux
Ghostscript security update (CESA-2018:3650) ghostscript-9.07-31.el7_6.1.i686.rpmLinux
Ghostscript security update (CESA-2018:3650) ghostscript-9.07-31.el7_6.1.x86_64.rpmLinux
Ghostscript security update (CESA-2018:3650) ghostscript-doc-9.07-31.el7_6.1.noarch.rpmLinux
Ghostscript security update (CESA-2018:3650) ghostscript-gtk-9.07-31.el7_6.1.x86_64.rpmLinux
Ghostscript security update (CESA-2018:3650) ghostscript-cups-9.07-31.el7_6.1.x86_64.rpmLinux
Ghostscript security update (CESA-2018:3650) ghostscript-devel-9.07-31.el7_6.1.i686.rpmLinux
Ghostscript security update (CESA-2018:3650) ghostscript-devel-9.07-31.el7_6.1.x86_64.rpmLinux
(RHSA-2018:3650) ghostscript security update ghostscript-9.07-31.el7_6.1.i686.rpmLinux
(RHSA-2018:3650) ghostscript security update ghostscript-9.07-31.el7_6.1.x86_64.rpmLinux
(RHSA-2018:3650) ghostscript security update ghostscript-cups-9.07-31.el7_6.1.x86_64.rpmLinux
(RHSA-2018:3650) ghostscript security update ghostscript-devel-9.07-31.el7_6.1.i686.rpmLinux
(RHSA-2018:3650) ghostscript security update ghostscript-devel-9.07-31.el7_6.1.x86_64.rpmLinux
(RHSA-2018:3650) ghostscript security update ghostscript-doc-9.07-31.el7_6.1.noarch.rpmLinux
(RHSA-2018:3650) ghostscript security update ghostscript-gtk-9.07-31.el7_6.1.x86_64.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-fonts-other-8.62-32.47.13.1.i586.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-fonts-other-8.62-32.47.13.1.x86_64.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-fonts-rus-8.62-32.47.13.1.i586.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-fonts-rus-8.62-32.47.13.1.x86_64.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-fonts-std-8.62-32.47.13.1.i586.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-fonts-std-8.62-32.47.13.1.x86_64.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-library-8.62-32.47.13.1.i586.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-library-8.62-32.47.13.1.x86_64.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-omni-8.62-32.47.13.1.i586.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-omni-8.62-32.47.13.1.x86_64.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-x11-8.62-32.47.13.1.i586.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) ghostscript-x11-8.62-32.47.13.1.x86_64.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) libgimpprint-4.2.7-32.47.13.1.i586.rpmLinux
SUSE-SU-2018:3330-1(SUSE Linux Enterprise Server 11-SP4 ) libgimpprint-4.2.7-32.47.13.1.x86_64.rpmLinux
ghostscript Security Update (ALAS-2018-1088) ghostscript-devel-9.06-8.amzn2.0.5.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234