CVE Database
/

CVE-2019-14813

Back to search

CVE-2019-14813

Published: Sep 6, 2019

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

7.3

HIGH

Description

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

VendorProductVersions

Artifex Software

ghostscript

affected
ghostscript versions 9.x before 9.28

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

References

DSA-4518
vendor-advisory
x_refsource_DEBIAN
RHSA-2019:2594
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-0a9d525d71
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-953fc0f16d
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-ebd6c4f15a
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:2222
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2223
vendor-advisory
x_refsource_SUSE
RHBA-2019:2824
vendor-advisory
x_refsource_REDHAT
GLSA-202004-03
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now