CVE-2018-15909
27.08.2018, 17:29
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.Enginsight
Vendor | Product | Version |
---|---|---|
debian | debian_linux | 8.0 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
artifex | ghostscript | 𝑥 ≤ 9.23 |
artifex | gpl_ghostscript | 𝑥 < 9.26 |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server_aus | 7.6 |
redhat | enterprise_linux_server_eus | 7.6 |
redhat | enterprise_linux_server_tus | 7.6 |
redhat | enterprise_linux_workstation | 7.0 |
pulsesecure | pulse_connect_secure | 8.2r1.0 ≤ 𝑥 < 8.2r12.1 |
pulsesecure | pulse_connect_secure | 8.3r1 ≤ 𝑥 < 8.3r7.1 |
pulsesecure | pulse_connect_secure | 9.0r1 ≤ 𝑥 < 9.0r3.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References