CVE-2018-15910: Incorrect Type Cast
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
Other sources
It was discovered that the type of the LockDistillerParams parameter is not properly verified. A specially crafted PostScript document could possibly exploit this to crash ghostscript or, possibly, execute arbitrary code in the context of the ghostscript process.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-15910?
CVE-2018-15910 is a vulnerability in Artifex Ghostscript before 9.24 that allows attackers to crash the interpreter or execute code by supplying crafted PostScript files.
Which software is affected by CVE-2018-15910?
CVE-2018-15910 affects Artifex Ghostscript versions up to and including 9.24, Debian Linux 8.0 and 9.0, Canonical Ubuntu Linux 14.04, 16.04, and 18.04, Redhat Enterprise Linux Desktop, Server, and Workstation 7.0, Redhat Enterprise Linux Server Eus 7.5, Artifex GPL Ghostscript up to 9.26, and Pulsesecure Pulse Connect Secure versions 8.2r1.0 to 8.2r12.1, 8.3r1 to 8.3r7.1, and 9.0r1 to 9.0r3.4.
What is the severity rating of CVE-2018-15910?
CVE-2018-15910 has a severity rating of 7.8 (high).
How can I fix CVE-2018-15910?
To fix CVE-2018-15910, update Artifex Ghostscript to version 9.24, Debian Linux to the recommended version, Canonical Ubuntu Linux to the recommended version, Redhat Enterprise Linux to the recommended version, Artifex GPL Ghostscript to version 9.27, and Pulsesecure Pulse Connect Secure to the recommended version.
Where can I find more information about CVE-2018-15910?
You can find more information about CVE-2018-15910 at the following references: [http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=c3476dde7743761a4e1d39a631716199b696b880], [https://www.kb.cert.org/vuls/id/332928], [https://bugs.ghostscript.com/show_bug.cgi?id=699656].