High severity7.8NVD Advisory· Published Dec 20, 2018· Updated Jun 17, 2026
CVE-2018-19134
CVE-2018-19134
Description
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9<=9.25+ 2 more
- (no CPE)range: <=9.25
- cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*range: <=9.25
- (no CPE)range: <=9.25
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- semmle.com/news/semmle-discovers-severe-vulnerability-ghostscript-postscript-pdfnvdExploitThird Party Advisory
- www.securityfocus.com/bid/106278nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:3834nvdThird Party Advisory
- bugs.ghostscript.com/show_bug.cginvdIssue TrackingPermissions RequiredThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/12/msg00019.htmlnvdThird Party Advisory
- www.ghostscript.com/doc/9.26/News.htmnvdRelease Notes
- git.ghostscript.comnvd
News mentions
0No linked articles in our index yet.