ZeroHour

CVE-2019-3835

CVSS 3.1
5.5 medium
EPSS
2%p84
Published
()
Modified
Description

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

Vendors
artifexredhatfedoraprojectdebianopensuse
Products
ghostscript, ansible tower, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, fedora, debian linux, leap
Weakness
CWE-648, CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.