PT-2019-3236 · Artifex+5 · Ghostscript+5

Cedric Buissart

+1

·

Publicado

2019-08-20

·

Atualizado

2024-02-28

·

CVE-2019-14812

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostscript versions 9.x before 9.50
Description A flaw in the .setuserparams2 procedure of Ghostscript allows scripts to bypass -dSAFER restrictions by not properly securing its privileged calls. This enables a specially crafted PostScript file to disable security protection, access the file system, or execute arbitrary commands. The issue is related to the incorrect use of privileged APIs, which can be exploited by a remote attacker to execute arbitrary commands or access the file system, bypassing the restrictions imposed by -dSAFER.
Recommendations For Ghostscript versions 9.x before 9.50, update to version 9.50 or later to resolve the issue. As a temporary workaround, consider disabling the use of the .setuserparams2 procedure until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation. Avoid using specially crafted PostScript files that could exploit this issue until the software is updated.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2669
ALT-PU-2020-2917
ALT-PU-2020-2921
ALT-PU-2020-3124
BDU:2019-03226
CESA-2019_2586
CESA-2019_2591
CVE-2019-14812
DLA-1915-1
DSA-4518-1
MGASA-2019-0271
OPENSUSE-SU-2019:2222-1
OPENSUSE-SU-2019:2223-1
OPENSUSE-SU-2019_2222-1
OPENSUSE-SU-2019_2223-1
RHSA-2019:2586
RHSA-2019:2591
RHSA-2019_2586
RHSA-2019_2591
SUSE-SU-2019:2460-1
SUSE-SU-2019:2478-1
USN-4111-1

Produtos afetados

Alt Linux
Centos
Ghostscript
Red Hat
Suse
Ubuntu