CVE-2018-19134
A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.87%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.87% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-704
- Affected
- artifex/ghostscript · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=693baf02152119af6e6afd30bb8ec76d14f84bbf
- http://www.securityfocus.com/bid/106278Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3834Third Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=700141Issue Tracking, Permissions Required, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/12/msg00019.htmlThird Party Advisory
- https://semmle.com/news/semmle-discovers-severe-vulnerability-ghostscript-postscript-pdfExploit, Third Party Advisory
- https://www.ghostscript.com/doc/9.26/News.htmRelease Notes
- http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=693baf02152119af6e6afd30bb8ec76d14f84bbf
- http://www.securityfocus.com/bid/106278Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3834Third Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=700141Issue Tracking, Permissions Required, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/12/msg00019.htmlThird Party Advisory
- https://semmle.com/news/semmle-discovers-severe-vulnerability-ghostscript-postscript-pdfExploit, Third Party Advisory
- https://www.ghostscript.com/doc/9.26/News.htmRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.