CVE-2018-10194: Buffer Overflow
Last updated 25 August 2025
Other sources
pdfsettextmatrix in gdevpdts.c in Artifex Ghostscript through 9.18 allows remote attackers to cause a denial of service (spprint.c pprintg1 stack-based out-of-bounds write) or possibly execute arbitrary code via a crafted PDF document.
— Red Hat
The settextdistance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10194?
CVE-2018-10194 has been rated as a high severity vulnerability due to its potential for remote code execution and denial of service.
How do I fix CVE-2018-10194?
To fix CVE-2018-10194, upgrade to Ghostscript versions 9.24 or later for Red Hat and 9.21~dfsg+1-0ubuntu3.1 for Ubuntu.
What should I do if I cannot upgrade to a patched version for CVE-2018-10194?
If you cannot upgrade, consider implementing strict access controls or disabling the use of Ghostscript to mitigate the risks associated with CVE-2018-10194.
What type of exploit is associated with CVE-2018-10194?
CVE-2018-10194 is associated with stack-based buffer overflow vulnerabilities that can be triggered by processing crafted PDF documents.
Are there any known exploits for CVE-2018-10194?
Yes, CVE-2018-10194 can be exploited through specially crafted PDF files that cause denial of service or arbitrary code execution.