CVE-2018-19134: Artifex Ghostscript
High severity, CVSS 7.8. EPSS: 2.9% chance of exploitation in the next 30 days.
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
Affected products
- Artifex Ghostscript: up to and including 9.25
- Debian Debian Linux: version 8.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-12-20. Last modified 2026-06-17.