CVE-2018-16513: Incorrect Type Cast
Published Sep 5, 2018
·Updated
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
Affected Software
11 affected componentsFixes available
Artifex Ghostscript<9.24
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Artifex Gpl Ghostscript<9.26
PulseSecure Pulse Connect Secure>=8.2r1.0<8.2r12.1
PulseSecure Pulse Connect Secure>=8.3r1<8.3r7.1
PulseSecure Pulse Connect Secure>=9.0r1<9.0r3.4
debian/ghostscript
9.53.3~dfsg-7+deb11u79.53.3~dfsg-7+deb11u1110.0.0~dfsg-11+deb12u810.05.1~dfsg-1+deb13u110.06.0~dfsg-3
Remediation
Patch Available
Event History
Sep 5, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·04:13 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:13 PM
DescriptionAffected Software
Data Sourced
via Launchpad·04:13 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16513?
CVE-2018-16513 is a vulnerability in Artifex Ghostscript before 9.24 that allows attackers to supply crafted PostScript files and potentially crash the interpreter or have other unspecified impact.
2
How can I exploit CVE-2018-16513?
You can exploit CVE-2018-16513 by supplying crafted PostScript files to the vulnerable Artifex Ghostscript software.
3
What is the severity rating of CVE-2018-16513?
CVE-2018-16513 has a severity rating of 7.8 (high).
4
Which versions of Artifex Ghostscript are affected by CVE-2018-16513?
Versions before 9.24 of Artifex Ghostscript are affected by CVE-2018-16513.
5
How can I fix CVE-2018-16513?
To fix CVE-2018-16513, update Artifex Ghostscript to version 9.24 or later.