Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-6116

Опубликовано: 23 янв. 2019
Источник: redhat
CVSS3: 7.3
EPSS Средний

Описание

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

It was found that ghostscript could leak sensitive operators on the operand stack when a pseudo-operator pushes a subroutine. A specially crafted PostScript file could use this flaw to escape the -dSAFER protection in order to, for example, have access to the file system outside of the SAFER constraints.

Отчет

Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Important, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Меры по смягчению последствий

Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ghostscriptWill not fix
Red Hat Enterprise Linux 6ghostscriptWill not fix
Red Hat Enterprise Linux 8ghostscriptNot affected
Red Hat Enterprise Linux 7ghostscriptFixedRHSA-2019:022931.01.2019

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1666636ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)

EPSS

Процентиль: 99%
0.67767
Средний

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

CVSS3: 7.8
nvd
больше 6 лет назад

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

CVSS3: 7.8
debian
больше 6 лет назад

In Artifex Ghostscript through 9.26, ephemeral or transient procedures ...

suse-cvrf
больше 6 лет назад

Security update for ghostscript

suse-cvrf
почти 7 лет назад

Security update for ghostscript

EPSS

Процентиль: 99%
0.67767
Средний

7.3 High

CVSS3