SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-16541

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.

MEDIUM 5.5EPSS 1.41%

Does this matter?

Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.

Description

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.

CVSS 3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
1.41% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-416
Affected
artifex/ghostscript · canonical/ubuntu linux · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.