« List of all CVEs

CVE-2019-14812

Published: 11/27/2019 Last updated: 8/5/2024 Reserved: 8/10/2019

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 7.3 High CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Opam packages affected (1)

conf-ghostscript

Products affected (1)

Product Vendor Version
ghostscript Red Hat 2008 for x64-based Systems Service Pack 2

References (12)