Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14869

Опубликовано: 14 нояб. 2019
Источник: redhat
CVSS3: 7.3

Описание

A flaw was found in all versions of ghostscript 9.x before 9.50, where the .charkeys procedure, where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.

A flaw was found in the .charkeys procedure, where it did not properly secure its privileged calls, enabling scripts to bypass -dSAFER restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.

Меры по смягчению последствий

Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 2ghostscriptNot affected
Red Hat Enterprise Linux 5ghostscriptNot affected
Red Hat Enterprise Linux 6ghostscriptNot affected
Red Hat Enterprise Linux 7ghostscriptFixedRHSA-2019:388814.11.2019
Red Hat Enterprise Linux 8ghostscriptFixedRHSA-2019:389018.11.2019
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsghostscriptFixedRHSA-2020:022223.01.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-648
https://bugzilla.redhat.com/show_bug.cgi?id=1768911ghostscript: -dSAFER escape in .charkeys (701841)

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.

CVSS3: 8.8
nvd
около 6 лет назад

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.

CVSS3: 8.8
debian
около 6 лет назад

A flaw was found in all versions of ghostscript 9.x before 9.50, where ...

suse-cvrf
около 6 лет назад

Security update for ghostscript

suse-cvrf
около 6 лет назад

Security update for ghostscript

7.3 High

CVSS3