Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxr2-p327-97jr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.28 are vulnerable.

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.28 are vulnerable.

EPSS

Процентиль: 34%
0.00132
Низкий

7.8 High

CVSS3

Дефекты

CWE-648

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

CVSS3: 7.3
redhat
больше 6 лет назад

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

CVSS3: 7.8
nvd
больше 6 лет назад

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

CVSS3: 7.8
debian
больше 6 лет назад

It was found that in ghostscript some privileged operators remained ac ...

oracle-oval
больше 6 лет назад

ELSA-2019-1017: ghostscript security update (IMPORTANT)

EPSS

Процентиль: 34%
0.00132
Низкий

7.8 High

CVSS3

Дефекты

CWE-648