ZeroHour

CVE-2019-14813

CVSS 3.1
9.8 critical
EPSS
11%p96
Published
()
Modified
Description

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

Vendors
artifexredhatfedoraprojectopensusedebian
Products
ghostscript, openshift container platform, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, fedora, leap, debian linux
Weakness
CWE-648, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.