CVE-2018-16540: Use After Free
Published Sep 5, 2018
·Updated
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
Affected Software
18 affected componentsFixes available
redhat/ghostscript<9.24
9.24
Artifex Ghostscript<9.24
redhat OpenShift Container Platform=3.11
redhat Enterprise Linux=7.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server=7.6
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
debian/ghostscript
9.53.3~dfsg-7+deb11u79.53.3~dfsg-7+deb11u1110.0.0~dfsg-11+deb12u810.05.1~dfsg-1+deb13u110.06.0~dfsg-3
Remediation
Patch Available
Event History
Sep 5, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·04:13 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:13 PM
DescriptionAffected Software
Data Sourced
via Launchpad·04:13 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16540?
CVE-2018-16540 is a vulnerability in Artifex Ghostscript before 9.24 that allows attackers to supply crafted PostScript files to the PDF14 converter, leading to a use-after-free issue in copydevice handling.
2
How severe is CVE-2018-16540?
CVE-2018-16540 has a severity rating of 7.8, which is considered high.
3
Which software versions are affected by CVE-2018-16540?
Versions of Artifex Ghostscript before 9.24 are affected by CVE-2018-16540.
4
How can I fix CVE-2018-16540?
To fix CVE-2018-16540, update Artifex Ghostscript to version 9.24 or later.
5
Where can I find more information about CVE-2018-16540?
More information about CVE-2018-16540 can be found in the references provided.