7.8
CVE-2018-15911
- EPSS 2.7%
- Published 28.08.2018 04:29:00
- Last modified 21.11.2024 03:51:42
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
Data is provided by the National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version8.0
Debian ≫ Debian Linux Version9.0
Canonical ≫ Ubuntu Linux Version14.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version16.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version18.04 SwEditionlts
Artifex ≫ Ghostscript Version <= 9.23
Artifex ≫ Gpl Ghostscript Version < 9.26
Redhat ≫ Enterprise Linux Desktop Version7.0
Redhat ≫ Enterprise Linux Server Version7.0
Redhat ≫ Enterprise Linux Server Aus Version7.6
Redhat ≫ Enterprise Linux Server Eus Version7.6
Redhat ≫ Enterprise Linux Server Tus Version7.6
Redhat ≫ Enterprise Linux Workstation Version7.0
Pulsesecure ≫ Pulse Connect Secure Version >= 8.2r1.0 < 8.2r12.1
Pulsesecure ≫ Pulse Connect Secure Version >= 8.3r1 < 8.3r7.1
Pulsesecure ≫ Pulse Connect Secure Version >= 9.0r1 < 9.0r3.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.7% | 0.853 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-908 Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.