An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2018:3650 | third party advisory vendor advisory |
https://security.gentoo.org/glsa/201811-12 | third party advisory vendor advisory |
https://usn.ubuntu.com/3768-1/ | third party advisory vendor advisory |
http://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=0edd3d6c634a577db261615a9dc2719bca7f6e01 | |
https://www.artifex.com/news/ghostscript-security-resolved/ | patch vendor advisory |
https://www.debian.org/security/2018/dsa-4288 | third party advisory vendor advisory |
https://bugs.ghostscript.com/show_bug.cgi?id=699659 | third party advisory permissions required |
https://lists.debian.org/debian-lts-announce/2018/09/msg00015.html | third party advisory mailing list |
http://seclists.org/oss-sec/2018/q3/182 | issue tracking mailing list patch third party advisory |