CVE-2018-15911: High severity debian linux vulnerability
Published Aug 28, 2018
·Updated
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
Affected Software
18 affected componentsFixes available
redhat/ghostscript<9.24
9.24
debian/ghostscript
9.53.3~dfsg-7+deb11u79.53.3~dfsg-7+deb11u910.0.0~dfsg-11+deb12u610.04.0~dfsg-2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Artifex Ghostscript<=9.23
Artifex Gpl Ghostscript<9.26
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=7.0
PulseSecure Pulse Connect Secure>=8.2r1.0<8.2r12.1
PulseSecure Pulse Connect Secure>=8.3r1<8.3r7.1
PulseSecure Pulse Connect Secure>=9.0r1<9.0r3.4
Remediation
Patch Available
Event History
Aug 28, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:53 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:51 PM
RemedyDescriptionSeverityAffected Software
Nov 30, 2024
Data Sourced
via Debian·08:47 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-15911?
CVE-2018-15911 is a vulnerability in Artifex Ghostscript 9.23 before 2018-08-24 that allows attackers to use uninitialized memory access to crash the interpreter or potentially execute code.
2
How severe is CVE-2018-15911?
CVE-2018-15911 has a severity score of 7.8, indicating a high severity.
3
Which software versions are affected by CVE-2018-15911?
Artifex Ghostscript versions before 9.24 are affected by CVE-2018-15911.
4
How can I fix CVE-2018-15911?
To fix CVE-2018-15911, upgrade to Artifex Ghostscript version 9.24.
5
Where can I find more information about CVE-2018-15911?
More information about CVE-2018-15911 can be found at the following references: [1][2][3].