CVE-2018-19477: Incorrect Type Cast
A vulnerability was found in Artifex Ghostscript before 9.26. A JBIG2Decode type confusion in psi/zfjbig2.c allows remote attackers to bypass intended access restrictions.
References: https://bugs.ghostscript.com/showbug.cgi?id=700168 https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26
Upstream Patches: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ef252e7dc214bcbd9a2539216aab9202848602bb http://git.ghostscript.com/?p=ghostpdl.git;h=606a22e77e7f081781e99e44644cd0119f559e03
Other sources
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19477?
CVE-2018-19477 has a medium severity rating due to its potential to allow remote attackers to bypass access restrictions.
How do I fix CVE-2018-19477?
To fix CVE-2018-19477, upgrade Ghostscript to version 9.26 or later.
Which versions of Ghostscript are affected by CVE-2018-19477?
Versions of Ghostscript prior to 9.26 are affected by CVE-2018-19477.
Can CVE-2018-19477 be exploited remotely?
Yes, CVE-2018-19477 can be exploited remotely, allowing unauthorized access.
What systems are impacted by CVE-2018-19477?
CVE-2018-19477 impacts various systems including Debian, Ubuntu, and Red Hat running vulnerable versions of Ghostscript.