Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3838

Опубликовано: 25 мар. 2019
Источник: debian
EPSS Низкий

Описание

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ghostscriptfixed9.27~~dc1~dfsg-1experimentalpackage
ghostscriptfixed9.27~dfsg-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2019/03/21/1

  • https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=ed9fcd95bb01f0768bf273b2526732e381202319

  • https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=a82601e8f95a2f2147f3b3b9e44ec2b8f3a6be8b

  • https://bugs.ghostscript.com/show_bug.cgi?id=700576

EPSS

Процентиль: 80%
0.01413
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

CVSS3: 7.3
redhat
больше 6 лет назад

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

CVSS3: 5.5
nvd
больше 6 лет назад

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

suse-cvrf
больше 6 лет назад

Security update for ghostscript

suse-cvrf
больше 6 лет назад

Security update for ghostscript

EPSS

Процентиль: 80%
0.01413
Низкий