CVE-2018-19134: Artifex Ghostscript

High severity, CVSS 7.8. EPSS: 2.9% chance of exploitation in the next 30 days.

In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.

Affected products

  • Artifex Ghostscript: up to and including 9.25
  • Debian Debian Linux: version 8.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-12-20. Last modified 2026-06-17.