Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-3839

Опубликовано: 16 мая 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

РелизСтатусПримечание
bionic

released

9.26~dfsg+0-0ubuntu0.18.04.9
cosmic

released

9.26~dfsg+0-0ubuntu0.18.10.9
devel

released

9.26~dfsg+0-0ubuntu8
disco

released

9.26~dfsg+0-0ubuntu7.1
esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

9.26~dfsg+0-0ubuntu0.18.04.9
esm-infra/xenial

released

9.26~dfsg+0-0ubuntu0.16.04.9
precise/esm

DNE

trusty/esm

DNE

upstream

released

9.27~dfsg-1

Показывать по

EPSS

Процентиль: 34%
0.00132
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
больше 6 лет назад

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

CVSS3: 7.8
nvd
больше 6 лет назад

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

CVSS3: 7.8
debian
больше 6 лет назад

It was found that in ghostscript some privileged operators remained ac ...

CVSS3: 7.8
github
больше 3 лет назад

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.28 are vulnerable.

oracle-oval
больше 6 лет назад

ELSA-2019-1017: ghostscript security update (IMPORTANT)

EPSS

Процентиль: 34%
0.00132
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3