Command Injection in Ghostscript - CVE-2019-6116
Published: January 27, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to leak of sensitive operators on the operand stack when a pseudo-operator pushes a subroutine. A remote unauthenticated attacker can supply a specially crafted PostScript file to escape the -dSAFER protection, gain access to the file system and execute arbitrary commands.
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
ghostscript (Alpine package)
busybox (Alpine package)
ghostscript (Debian package)
firefox-esr (Alpine package)
ghostscript
How to mitigate CVE-2019-6116
ghostscript (Alpine package) - update to 9.26-r1
ghostscript (Debian package) - update to 9.26a~dfsg-0+deb9u1
ghostscript - addressed in versions 9.26-3.fc28, 9.26-3.fc29, 9.26-3.fc30, 9.27-1.fc29, 9.27-1.fc30, 9.27-1.fc31
External References
Related Security Bulletins
- Command injection in Artifex Ghostscript
- Debian update for ghostscript
- Arch Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- Arch Linux update for ghostscript
- Slackware Linux update for ghostscript
- Red Hat update for ghostscript
- Red Hat update for ghostscript
- Red Hat update for ghostscript
- Gentoo update for GPL Ghostscript
- Command Injection in ghostscript (Alpine package)
- Command Injection in busybox (Alpine package)
- Command Injection in firefox-esr (Alpine package)
- Fedora 29 update for ghostscript
- Fedora 28 update for ghostscript
- Fedora 30 update for ghostscript
- Fedora 29 update for ghostscript
- Fedora 30 update for ghostscript
- Fedora 31 update for ghostscript