CVE Database
/

CVE-2019-3839

Back to search

CVE-2019-3839

Published: May 16, 2019

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

7.3

HIGH

Description

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

VendorProductVersions

The ghostscript Project

ghostscript

affected
9.28

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

References

RHSA-2019:0971
vendor-advisory
x_refsource_REDHAT
RHSA-2019:1017
vendor-advisory
x_refsource_REDHAT
USN-3970-1
vendor-advisory
x_refsource_UBUNTU
DSA-4442
vendor-advisory
x_refsource_DEBIAN
FEDORA-2019-953fc0f16d
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-ebd6c4f15a
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:2222
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2223
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now