CVE-2018-19476: Incorrect Type Cast
A vulnerability was found in Artifex Ghostscript before 9.26. A type confusion in setcolorspace in psi/zicc.c allows remote attackers to bypass intended access restrictions.
References: https://bugs.ghostscript.com/showbug.cgi?id=700169 https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26
Upstream Patches: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=67d760ab775dae4efe803b5944b0439aa3c0b04a http://git.ghostscript.com/?p=ghostpdl.git;h=548bb434e81dadcc9f71adf891a3ef5bea8e2b4e
Other sources
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19476?
CVE-2018-19476 has been classified as a medium severity vulnerability.
How do I fix CVE-2018-19476?
To fix CVE-2018-19476, upgrade to Ghostscript version 9.26 or later.
What type of vulnerability is CVE-2018-19476?
CVE-2018-19476 is a type confusion vulnerability in the setcolorspace function.
Which versions of Ghostscript are affected by CVE-2018-19476?
Ghostscript versions prior to 9.26 are affected by CVE-2018-19476.
Can CVE-2018-19476 be exploited remotely?
Yes, CVE-2018-19476 allows remote attackers to bypass access restrictions.