OS Command Injection in Ghostscript - CVE-2019-3838
Published: March 22, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing PostScript files with Ghostscript. A remote attacker can create a specially crafted PDF file, trick the victim to open it and execute arbitrary commands on the affected system.
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
ghostscript (Alpine package)
busybox (Alpine package)
ghostscript (Debian package)
firefox-esr (Alpine package)
ghostscript
How to mitigate CVE-2019-3838
ghostscript (Debian package) - update to 9.26a~dfsg-0+deb9u2
ghostscript - addressed in versions 9.26-4.fc28, 9.26-4.fc29, 9.26-4.fc30
External References
Related Security Bulletins
- Remote code execution in Ghostscript
- Debian update for ghostscript
- Arch Linux update for ghostscript
- Slackware Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- OpenSUSE Linux update for ghostscript
- Red Hat update for ghostscript
- Red Hat update for ghostscript
- Gentoo update for GPL Ghostscript
- OS Command Injection in ghostscript (Alpine package)
- OS Command Injection in busybox (Alpine package)
- OS Command Injection in firefox-esr (Alpine package)
- Fedora 28 update for ghostscript
- Fedora 29 update for ghostscript
- Fedora 30 update for ghostscript