Artifex · Ghostscript · CVE-2019-14869
**Name of the Vulnerable Software and Affected Versions**
ghostscript versions 9.x before 9.50
**Description**
A flaw in the `.charkeys` procedure of ghostscript allows scripts to bypass `-dSAFER` restrictions by not properly securing its privileged calls. This enables an attacker to create a specially crafted PostScript file that could escalate privileges within Ghostscript, access files outside of restricted areas, or execute commands. The exploitation of this flaw may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
**Recommendations**
For ghostscript versions 9.x before 9.50, update to version 9.50 or later to resolve the issue. As a temporary workaround, consider restricting access to the `.charkeys` procedure to minimize the risk of exploitation. Avoid using the `-dSAFER` restrictions in affected versions until the issue is resolved.