Exposed dangerous method or function in Ghostscript - CVE-2019-3835

 

Exposed dangerous method or function in Ghostscript - CVE-2019-3835

Published: April 17, 2019


Vulnerability identifier: #VU18288
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3835
CWE-ID: CWE-749
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due presence of superexec operator within the internal dictionary. A remote attacker can create a specially crafted PDF file, trick the victim into opening, bypass system restrictions of the dSAFER sandbox and access files on the system.

Affected software

Ghostscript
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
Fedora
busybox (Alpine package)
ghostscript (Debian package)
ghostscript (Alpine package)
firefox-esr (Alpine package)
ghostscript

How to mitigate CVE-2019-3835

Install updates from vendor's website.

Ghostscript - update to 9.27
ghostscript (Debian package) - update to 9.26a~dfsg-0+deb9u2
ghostscript (Alpine package) - update to 9.26-r2
ghostscript - addressed in versions 9.26-4.fc28, 9.26-4.fc29, 9.26-4.fc30

External References

Related Security Bulletins