CVE-2018-15909

HIGH7.8EPSS 2.1%
Published: 8/27/2018Modified: 12/3/2025
Also known as:ALPINE-CVE-2018-15909DEBIAN-CVE-2018-15909

Description

In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.8CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References (2)