PT-2019-3237 · Artifex+5 · Ghostscript+5

Publicado

2019-08-20

·

Atualizado

2020-10-25

·

CVE-2019-14813

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ghostscript versions 9.x before 9.50
Description A flaw in the setsystemparams procedure of ghostscript enables scripts to bypass -dSAFER restrictions. This allows a specially crafted PostScript file to disable security protection, potentially granting access to the file system or enabling the execution of arbitrary commands.
Recommendations For ghostscript versions 9.x before 9.50, update to version 9.50 or later to resolve the issue. As a temporary workaround, consider restricting access to the setsystemparams procedure until a patch is available. Avoid using the setsystemparams procedure in sensitive environments until the issue is resolved.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2669
ALT-PU-2020-2917
ALT-PU-2020-2921
ALT-PU-2020-3124
BDU:2019-03227
CESA-2019_2586
CESA-2019_2591
CVE-2019-14813
DLA-1915-1
DSA-4518-1
MGASA-2019-0271
OPENSUSE-SU-2019:2222-1
OPENSUSE-SU-2019:2223-1
OPENSUSE-SU-2019_2222-1
OPENSUSE-SU-2019_2223-1
RHSA-2019:2586
RHSA-2019:2591
RHSA-2019_2586
RHSA-2019_2591
SUSE-SU-2019:2460-1
SUSE-SU-2019:2478-1
USN-4111-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Ghostscript