OS Command Injection in Ghostscript - CVE-2019-3838

 

OS Command Injection in Ghostscript - CVE-2019-3838

Published: March 22, 2019


Vulnerability identifier: #VU18055
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3838
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing PostScript files with Ghostscript. A remote attacker can create a specially crafted PDF file, trick the victim to open it and execute arbitrary commands on the affected system.


Affected software

Ghostscript
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
ghostscript (Alpine package)
busybox (Alpine package)
ghostscript (Debian package)
firefox-esr (Alpine package)
ghostscript

How to mitigate CVE-2019-3838

Install updates from vendor's repository.

ghostscript (Alpine package) - update to 9.26-r2
ghostscript (Debian package) - update to 9.26a~dfsg-0+deb9u2
ghostscript - addressed in versions 9.26-4.fc28, 9.26-4.fc29, 9.26-4.fc30

External References

Related Security Bulletins