CVE-2018-19134
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
- Affected products
- Alt Linux, Artifex Ghostscript, Centos, Red Hat
- Artifex Ghostscript
- ≤ 9.25
- Fix
- Available
- CVSS 3.0
- 7.8 HIGH
- EPSS
- 2.9% (85th percentile)
- Weakness
- CWE-704
- NVD status
- Modified
- Published
- 2018-12-20
CVE-2018-19134 at NVD
No indexed exploits for CVE-2018-19134 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-19134 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.