« List of all CVEs

CVE-2019-14817

Published: 9/3/2019 Last updated: 8/5/2024 Reserved: 8/10/2019

A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 7.3 High CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Opam packages affected (1)

conf-ghostscript

Products affected (1)

Product Vendor Version
ghostscript Artifex Software QCA6574

References (26)