Command Injection in Ghostscript - CVE-2019-6116

 

Command Injection in Ghostscript - CVE-2019-6116

Published: January 27, 2019


Vulnerability identifier: #VU17230
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6116
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The vulnerability exists due to leak of sensitive operators on the operand stack when a pseudo-operator pushes a subroutine. A remote unauthenticated attacker can supply a specially crafted PostScript file to escape the -dSAFER protection, gain access to the file system and execute arbitrary commands.


Affected software

Ghostscript
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
ghostscript (Alpine package)
busybox (Alpine package)
ghostscript (Debian package)
firefox-esr (Alpine package)
ghostscript

How to mitigate CVE-2019-6116

Update to version 9.26.

Ghostscript - update to 9.26
ghostscript (Alpine package) - update to 9.26-r1
ghostscript (Debian package) - update to 9.26a~dfsg-0+deb9u1
ghostscript - addressed in versions 9.26-3.fc28, 9.26-3.fc29, 9.26-3.fc30, 9.27-1.fc29, 9.27-1.fc30, 9.27-1.fc31

External References

Related Security Bulletins