ZeroHour

CVE-2019-3838

CVSS 3.1
5.5 medium
EPSS
2%p84
Published
()
Modified
Description

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

Vendors
artifexredhatfedoraprojectopensusedebian
Products
ghostscript, ansible tower, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, fedora, leap, debian linux
Weakness
CWE-648
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.