Description
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1792-1 | ghostscript security update |
Debian DLA |
DLA-2989-1 | ghostscript security update |
Debian DSA |
DSA-4442-1 | ghostscript security update |
EUVD |
EUVD-2019-13459 | It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable. |
Ubuntu USN |
USN-3970-1 | Ghostscript vulnerability |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T19:19:18.593Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3839
No data.
Status : Modified
Published: 2019-05-16T19:29:05.427
Modified: 2024-11-21T04:42:40.350
Link: CVE-2019-3839
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN