PT-2019-3236 · Artifex+5 · Ghostscript+5
Cedric Buissart
+1
·
Published
2019-08-20
·
Updated
2024-02-28
·
CVE-2019-14812
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ghostscript versions 9.x before 9.50
Description
A flaw in the .setuserparams2 procedure of Ghostscript allows scripts to bypass
-dSAFER restrictions by not properly securing its privileged calls. This enables a specially crafted PostScript file to disable security protection, access the file system, or execute arbitrary commands. The issue is related to the incorrect use of privileged APIs, which can be exploited by a remote attacker to execute arbitrary commands or access the file system, bypassing the restrictions imposed by -dSAFER.Recommendations
For Ghostscript versions 9.x before 9.50, update to version 9.50 or later to resolve the issue. As a temporary workaround, consider disabling the use of the
.setuserparams2 procedure until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation. Avoid using specially crafted PostScript files that could exploit this issue until the software is updated.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Ghostscript
Red Hat
Suse
Ubuntu