PT-2019-3237 · Artifex+5 · Ghostscript+5

Published

2019-08-20

·

Updated

2020-10-25

·

CVE-2019-14813

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ghostscript versions 9.x before 9.50
Description A flaw in the setsystemparams procedure of ghostscript enables scripts to bypass -dSAFER restrictions. This allows a specially crafted PostScript file to disable security protection, potentially granting access to the file system or enabling the execution of arbitrary commands.
Recommendations For ghostscript versions 9.x before 9.50, update to version 9.50 or later to resolve the issue. As a temporary workaround, consider restricting access to the setsystemparams procedure until a patch is available. Avoid using the setsystemparams procedure in sensitive environments until the issue is resolved.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2669
ALT-PU-2020-2917
ALT-PU-2020-2921
ALT-PU-2020-3124
BDU:2019-03227
CESA-2019_2586
CESA-2019_2591
CVE-2019-14813
DLA-1915-1
DSA-4518-1
MGASA-2019-0271
OPENSUSE-SU-2019:2222-1
OPENSUSE-SU-2019:2223-1
OPENSUSE-SU-2019_2222-1
OPENSUSE-SU-2019_2223-1
RHSA-2019:2586
RHSA-2019:2591
RHSA-2019_2586
RHSA-2019_2591
SUSE-SU-2019:2460-1
SUSE-SU-2019:2478-1
USN-4111-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Ghostscript