CVE-2019-10216
—CVSS 3.1
7.8 high
EPSS
2%p82
Published
()
Modified
Description
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
- Vendors
- artifexredhat
- Products
- ghostscript, 3scale api management, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation
- Weakness
- CWE-648
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.