Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-2465

Опубликовано: 13 авг. 2019
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2019-2465: ghostscript security update (IMPORTANT)

[9.25-2.2]

  • Resolves: #1737336 - CVE-2019-10216 ghostscript: -dSAFER escape via .buildfont1 (701394)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

ghostscript

9.25-2.el8_0.2

ghostscript-doc

9.25-2.el8_0.2

ghostscript-tools-dvipdf

9.25-2.el8_0.2

ghostscript-tools-fonts

9.25-2.el8_0.2

ghostscript-tools-printing

9.25-2.el8_0.2

ghostscript-x11

9.25-2.el8_0.2

libgs

9.25-2.el8_0.2

libgs-devel

9.25-2.el8_0.2

Oracle Linux x86_64

ghostscript

9.25-2.el8_0.2

ghostscript-doc

9.25-2.el8_0.2

ghostscript-tools-dvipdf

9.25-2.el8_0.2

ghostscript-tools-fonts

9.25-2.el8_0.2

ghostscript-tools-printing

9.25-2.el8_0.2

ghostscript-x11

9.25-2.el8_0.2

libgs

9.25-2.el8_0.2

libgs-devel

9.25-2.el8_0.2

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.

CVSS3: 7.3
redhat
больше 6 лет назад

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.

CVSS3: 7.8
nvd
около 6 лет назад

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.

CVSS3: 7.8
debian
около 6 лет назад

In ghostscript before version 9.50, the .buildfont1 procedure did not ...

suse-cvrf
больше 6 лет назад

Security update for ghostscript