CVE-2018-16511: Incorrect Type Cast
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
Other sources
It was discovered that the ghostscript type checker did not properly validate certain types. A specially crafted PostScript document could exploit this to crash ghostscript or, possibly, execute arbitrary code in the context of the ghostscript process.
Patch: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=0edd3d6c
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16511?
CVE-2018-16511 is a vulnerability in Artifex Ghostscript before version 9.24 that allows remote attackers to crash the interpreter or have other unspecified impacts by exploiting a type confusion in "ztype".
How severe is CVE-2018-16511?
CVE-2018-16511 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2018-16511?
Artifex Ghostscript versions before 9.24 are affected by CVE-2018-16511.
How can I fix CVE-2018-16511?
To fix CVE-2018-16511, update Artifex Ghostscript to version 9.24 or later.
Where can I find more information about CVE-2018-16511?
You can find more information about CVE-2018-16511 in the references provided: [Reference 1](http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=0edd3d6c634a577db261615a9dc2719bca7f6e01), [Reference 2](http://seclists.org/oss-sec/2018/q3/182), [Reference 3](https://www.artifex.com/news/ghostscript-security-resolved/).